PT-2021-12003 · Vaadin · Com.Vaadin:Flow-Server+1

Christian Knoop

·

Published

2021-04-19

·

Updated

2022-09-20

·

CVE-2020-36319

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: com.vaadin:flow-server versions 3.0.0 through 3.0.5 Vaadin versions 15.0.0 through 15.0.4
Description: The issue is related to an insecure configuration of the default ObjectMapper in the affected software. This may expose sensitive data if the application also uses certain annotations, such as @RestController.
Recommendations: For com.vaadin:flow-server versions 3.0.0 through 3.0.5, update the configuration of the default ObjectMapper to secure it. For Vaadin versions 15.0.0 through 15.0.4, update the configuration of the default ObjectMapper to secure it. As a temporary workaround, consider restricting the use of @RestController in applications using the affected versions until a secure configuration is applied.

Fix

Information Disclosure

Exposure of Resource to Wrong Sphere

Weakness Enumeration

Related Identifiers

CVE-2020-36319
GHSA-76F4-FW33-6J2V
GHSA-RJWW-2X8V-M9V9

Affected Products

Vaadin
Com.Vaadin:Flow-Server