Vulnerabilities in the Grails web framework and Ruby module TZInfo.
A vulnerability has been discovered in the Grails web framework, designed for developing web applications according to the MVC paradigm in Java, Groovy, and other JVM languages, allowing remote code execution in the environment where the web application is running. Exploitation of the vulnerability occurs through the submission of a specially crafted request that provides the attacker access to the ClassLoader. The issue is caused by an oversight in the data-binding logic, […]
