Description


Vulnerability in OSGi integration in com.vaadin:flow-server versions 1.2.0 through 2.4.7 (Vaadin 12.0.0 through 14.4.9), and 6.0.0 through 6.0.1 (Vaadin 19.0.0) allows attacker to access application classes and resources on the server via crafted HTTP request.

Related CPE's


a

vaadin

flow

2

a

vaadin

vaadin

2

Weaknesses



CWE-402


CWE-668

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

8.6 · High

Information


Source identifier

[email protected]

Vulnerability status

Modified

Published

2021-04-23T14:15:08.767Z

4 years ago

Last modified

2024-11-21T05:05:36.100Z

1 year ago