CVE-2014-2858

EUVD-2014-2882
Directory traversal vulnerability in the Resources plugin 1.0.0 before 1.2.6 for Pivotal Grails 2.0.0 through 2.3.6 allows remote attackers to obtain sensitive information via unspecified vectors related to a "configured block." NOTE: this issue was SPLIT from CVE-2014-0053 per ADT2 due to different vulnerability types.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 46%
Affected Products (NVD)
VendorProductVersion
gopivotalgrails-resources
1.0.0
gopivotalgrails-resources
1.0.2
gopivotalgrails-resources
1.1.0
gopivotalgrails-resources
1.1.1
gopivotalgrails-resources
1.1.2
gopivotalgrails-resources
1.1.4
gopivotalgrails-resources
1.1.5
gopivotalgrails-resources
1.1.6
gopivotalgrails-resources
1.2.0
gopivotalgrails-resources
1.2.1
gopivotalgrails-resources
1.2.2
gopivotalgrails-resources
1.2.3
gopivotalgrails-resources
1.2.4
gopivotalgrails-resources
1.2.5
gopivotalgrails
2.0.0
gopivotalgrails
2.0.1
gopivotalgrails
2.0.2
gopivotalgrails
2.0.3
gopivotalgrails
2.0.4
gopivotalgrails
2.1.0
gopivotalgrails
2.1.1
gopivotalgrails
2.1.2
gopivotalgrails
2.1.3
gopivotalgrails
2.1.4
gopivotalgrails
2.1.5
gopivotalgrails
2.2.0
gopivotalgrails
2.2.1
gopivotalgrails
2.2.2
gopivotalgrails
2.2.3
gopivotalgrails
2.2.4
gopivotalgrails
2.2.5
gopivotalgrails
2.3.0
gopivotalgrails
2.3.1
gopivotalgrails
2.3.2
gopivotalgrails
2.3.3
gopivotalgrails
2.3.4
gopivotalgrails
2.3.5
gopivotalgrails
2.3.6
𝑥
= Vulnerable software versions