PT-2021-19292 · Vaadin · Vaadin Designer

Published

2021-04-23

·

Updated

2021-05-04

·

CVE-2021-31410

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Vaadin Designer versions 4.3.0 through 4.6.3
Description The issue is related to an overly relaxed configuration of the frontend resources server, allowing remote attackers to access project sources via crafted HTTP requests.
Recommendations For Vaadin Designer versions 4.3.0 through 4.6.3, update to a version that addresses the overly relaxed configuration of the frontend resources server to prevent remote attackers from accessing project sources.

Fix

Exposure of Resource to Wrong Sphere

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-31410

Affected Products

Vaadin Designer