PT-2021-20230 · Vaadin · Vaadin-Server
Published
2021-10-13
·
Updated
2022-10-27
·
CVE-2021-33609
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions:
com.vaadin:vaadin-server versions 8.0.0 through 8.14.0
Description:
The issue is caused by a missing check in the
DataCommunicator class, allowing an authenticated network attacker to cause heap exhaustion by requesting too many rows of data.Recommendations:
For versions 8.0.0 through 8.14.0, consider disabling the
DataCommunicator class or restricting the amount of data that can be requested to prevent heap exhaustion until a patch is available.Fix
RCE
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Vaadin-Server