Description
In the development mode Grails provides a database console (available at /dbconsole/). This database console should not be available in the production environment as it leaks sensitive information about the database structure and permits executing SQL queries.
Remediation
It's recommended to restrict access to the database console by running Grails in production mode.
References
Related Vulnerabilities
WordPress Plugin Find My Blocks Information Disclosure (3.3.2)
Spring Boot Misconfiguration: Actuator endpoint security disabled
WordPress Plugin Video Embed & Thumbnail Generator Information Disclosure (1.1)
WordPress 4.1.x Multiple Vulnerabilities (4.1 - 4.1.24)
WordPress Plugin WP Import Export Information Disclosure (3.9.15)