CVE-2014-2858: Gopivotal Grails

Medium severity, CVSS 5.0. EPSS: 3.1% chance of exploitation in the next 30 days.

Directory traversal vulnerability in the Resources plugin 1.0.0 before 1.2.6 for Pivotal Grails 2.0.0 through 2.3.6 allows remote attackers to obtain sensitive information via unspecified vectors related to a "configured block." NOTE: this issue was SPLIT from CVE-2014-0053 per ADT2 due to different vulnerability types.

Affected products

  • Gopivotal Grails: version 2.0.0 only; version 2.0.1 only; version 2.0.2 only; version 2.0.3 only; version 2.0.4 only; version 2.1.0 only; …
  • Gopivotal Grails-Resources: version 1.0.0 only; version 1.0.2 only; version 1.1.0 only; version 1.1.1 only; version 1.1.2 only; version 1.1.4 only; …

Published 2014-04-15. Last modified 2026-06-17.