CVE-2021-33604

URL encoding error in development mode handler in com.vaadin:flow-server versions 2.0.0 through 2.6.1 (Vaadin 14.0.0 through 14.6.1), 3.0.0 through 6.0.9 (Vaadin 15.0.0 through 19.0.8) allows local user to execute arbitrary JavaScript code by opening crafted URL in browser.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
2.5 LOW
LOCAL
HIGH
NONE
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N
VaadinCNA
2.5 LOW
LOCAL
HIGH
NONE
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 16%
VendorProductVersion
vaadinflow-server
2.0.0 ≤
𝑥
≤ 2.6.1
vaadinflow-server
3.0.0 ≤
𝑥
≤ 5.0.0
vaadinflow-server
6.0.0 ≤
𝑥
≤ 6.0.9
vaadinvaadin
14.0.0 ≤
𝑥
≤ 14.6.1
vaadinvaadin
15.0.0 ≤
𝑥
≤ 18.0.0
vaadinvaadin
19.0.0 ≤
𝑥
≤ 19.0.8
𝑥
= Vulnerable software versions