Vulnerabilities in the Grails web framework and Ruby module TZInfo
A vulnerability has been identified in the Grails web framework, intended for developing web applications in accordance with the MVC paradigm using Java, Groovy, and other languages for the JVM, allowing remote code execution in the environment where the web application runs. Exploiting the vulnerability is done by sending a specially crafted request that grants the attacker access to the ClassLoader. The issue is caused by a shortcoming in the data-binding logic […]
