PT-2021-19287 · Vaadin · Com.Vaadin:Flow-Server+1

Xhelal Likaj

·

Published

2021-04-19

·

Updated

2021-04-30

·

CVE-2021-31406

CVSS v3.1

4.0

Medium

VectorAV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions com.vaadin:flow-server versions 3.0.0 through 5.0.3 com.vaadin:fusion-endpoint version 6.0.0
Description The issue is related to a non-constant-time comparison of CSRF tokens in the endpoint request handler. This allows an attacker to guess a security token for Fusion endpoints via a timing attack.
Recommendations For com.vaadin:flow-server versions 3.0.0 through 5.0.3, update to a version outside of this range to mitigate the risk. For com.vaadin:fusion-endpoint version 6.0.0, update to a version other than 6.0.0 to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable endpoint request handler until a patch is available.

Fix

Side Channel Attack

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-31406
GHSA-9H6G-6MXG-VVP4
GHSA-P7JQ-V8JP-J424

Affected Products

Com.Vaadin:Flow-Server
Com.Vaadin:Fusion-Endpoint