/static/WEB-INF/...
imagination.use { //Sensitive Information //Entire Codebase
yourBase.all.belongsTo(us) }
$ gvm use grails 2.3.5 $ grails create-app vuln
$ cd vuln $ grails compile $ grails run-war
curl http://localhost:8080/vuln/static/WEB-INF/classes/UrlMappings.class
runtime ":resources:1.2.7"
Prevent access to resources under /WEB-INF and /META-INF in the reverse proxy (if one is used)
includes/excludes
grails.resources.adhoc.includes = ['/images/**', '/css/**', '/js/**', '/plugins/**']
grails.resources.adhoc.excludes = ['**/WEB-INF/**','**/META-INF/**']