PT-2014-4924 · Pivotal · Pivotal Grails+1

Published

2014-04-15

·

Updated

2018-10-09

·

CVE-2014-2857

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Pivotal Grails versions 2.0.0 through 2.3.6 Resources plugin versions 1.0.0 through 1.2.5
Description The default configuration of the Resources plugin for Pivotal Grails does not properly restrict access to files in the META-INF directory. This allows remote attackers to obtain sensitive information via a direct request.
Recommendations For Pivotal Grails versions 2.0.0 through 2.3.6, update the Resources plugin to version 1.2.6 or later. For Resources plugin versions 1.0.0 through 1.2.5, update to version 1.2.6 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-2857

Affected Products

Pivotal Grails
Resources Plugin