PT-2017-8988 · Grails · Grails Console

Berdario

·

Published

2017-01-23

·

Updated

2017-01-26

·

CVE-2016-6521

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Grails console versions 1.5.10 and earlier Grails console version 2.0.7
Description A cross-site request forgery issue allows remote attackers to hijack user authentication for requests that execute arbitrary Groovy code.
Recommendations For Grails console version 2.0.7, update to a version that fixes this issue. For Grails console version 1.5.10 and earlier, update to a version that fixes this issue. As a temporary workaround, consider restricting access to the Grails console to minimize the risk of exploitation.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-6521

Affected Products

Grails Console