PatchSiren

Gopivotal CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Gopivotal CVE published 2017-01-23

CVE-2016-6521

CVE-2016-6521 was publicly recorded by NVD on 2017-01-23, following 2016 advisory and issue-tracker discussion. The issue is a cross-site request forgery (CSRF) weakness in Grails console, also referred to as Grails Debug Console and Grails Web Console. If an attacker can induce an authenticated user to submit a crafted request, the console may execute arbitrary Groovy code, which raises the impact from s [truncated]