CVE-2021-31407
23.04.2021, 16:15
Vulnerability in OSGi integration in com.vaadin:flow-server versions 1.2.0 through 2.4.7 (Vaadin 12.0.0 through 14.4.9), and 6.0.0 through 6.0.1 (Vaadin 19.0.0) allows attacker to access application classes and resources on the server via crafted HTTP request.
| Vendor | Product | Version |
|---|---|---|
| vaadin | flow | 1.2.0 ≤ 𝑥 < 2.4.8 |
| vaadin | flow | 6.0.0 ≤ 𝑥 < 6.0.2 |
| vaadin | vaadin | 12.0.0 ≤ 𝑥 < 14.4.10 |
| vaadin | vaadin | 19.0.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-402 - Transmission of Private Resources into a New Sphere ('Resource Leak')The software makes resources available to untrusted parties when those resources are only intended to be accessed by the software.
- CWE-668 - Exposure of Resource to Wrong SphereThe product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
References