PT-2021-19285 · Vaadin · Com.Vaadin:Flow-Server

Xhelal Likaj

·

Published

2021-04-19

·

Updated

2021-04-30

·

CVE-2021-31404

CVSS v3.1

4.0

Medium

VectorAV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions com.vaadin:flow-server versions 1.0.0 through 1.0.13 com.vaadin:flow-server versions 1.1.0 prior to 2.0.0 com.vaadin:flow-server versions 2.0.0 through 2.4.6 com.vaadin:flow-server versions 3.0.0 prior to 5.0.0 com.vaadin:flow-server versions 5.0.0 through 5.0.2
Description The issue is related to a non-constant-time comparison of CSRF tokens in the UIDL request handler, which allows an attacker to guess a security token via a timing attack.
Recommendations For com.vaadin:flow-server versions 1.0.0 through 1.0.13, update to a version outside of this range. For com.vaadin:flow-server versions 1.1.0 prior to 2.0.0, update to version 2.0.0 or later. For com.vaadin:flow-server versions 2.0.0 through 2.4.6, update to a version outside of this range. For com.vaadin:flow-server versions 3.0.0 prior to 5.0.0, update to version 5.0.0 or later. For com.vaadin:flow-server versions 5.0.0 through 5.0.2, update to a version outside of this range.

Fix

Side Channel Attack

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-31404
GHSA-C6C4-7X48-4CQP
GHSA-XWG3-QRCG-W9X6

Affected Products

Com.Vaadin:Flow-Server