CVE-2012-1833: Springsource Grails

Medium severity, CVSS 5.0. EPSS: 1.4% chance of exploitation in the next 30 days.

VMware SpringSource Grails before 1.3.8, and 2.x before 2.0.2, does not properly restrict data binding, which might allow remote attackers to bypass intended access restrictions and modify arbitrary object properties via a crafted request parameter to an application.

Affected products

  • Springsource Grails: up to and including 1.3.7; version 1.1.0 only; version 1.1.1 only; version 1.1.2 only; version 1.2.0 only; version 1.2.1 only; …

Published 2012-09-28. Last modified 2026-06-16.