PT-2021-19288 · Vaadin · Com.Vaadin:Flow-Server

Mstahvo

·

Published

2021-04-19

·

Updated

2022-08-12

·

CVE-2021-31407

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions com.vaadin:flow-server versions 1.2.0 through 2.4.7 com.vaadin:flow-server versions 6.0.0 through 6.0.1
Description The issue allows an attacker to access application classes and resources on the server via a crafted HTTP request. This is due to a vulnerability in OSGi integration in com.vaadin:flow-server.
Recommendations For com.vaadin:flow-server versions 1.2.0 through 2.4.7, update to a version outside of this range to resolve the issue. For com.vaadin:flow-server versions 6.0.0 through 6.0.1, update to a version outside of this range to resolve the issue. As a temporary workaround, consider restricting access to sensitive application classes and resources on the server until a patch is available.

Fix

Exposure of Resource to Wrong Sphere

Weakness Enumeration

Related Identifiers

CVE-2021-31407
GHSA-25XC-JWFQ-39JW
GHSA-J9WR-49VQ-RM5G

Affected Products

Com.Vaadin:Flow-Server