PT-2021-12003 · Vaadin · Com.Vaadin:Flow-Server+1
Christian Knoop
·
Published
2021-04-19
·
Updated
2022-09-20
·
CVE-2020-36319
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
com.vaadin:flow-server versions 3.0.0 through 3.0.5
Vaadin versions 15.0.0 through 15.0.4
Description:
The issue is related to an insecure configuration of the default
ObjectMapper in the affected software. This may expose sensitive data if the application also uses certain annotations, such as @RestController.Recommendations:
For com.vaadin:flow-server versions 3.0.0 through 3.0.5, update the configuration of the default
ObjectMapper to secure it.
For Vaadin versions 15.0.0 through 15.0.4, update the configuration of the default ObjectMapper to secure it.
As a temporary workaround, consider restricting the use of @RestController in applications using the affected versions until a secure configuration is applied.Fix
Information Disclosure
Exposure of Resource to Wrong Sphere
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Vaadin
Com.Vaadin:Flow-Server