Description
Vulnerability in OSGi integration in com.vaadin:flow-server versions 1.2.0 through 2.4.7 (Vaadin 12.0.0 through 14.4.9), and 6.0.0 through 6.0.1 (Vaadin 19.0.0) allows attacker to access application classes and resources on the server via crafted HTTP request.
Related CPE's
a
vaadin
flow
a
vaadin
vaadin
References
https://github.com/vaadin/flow/pull/10229
https://github.com/vaadin/flow/pull/10269
https://github.com/vaadin/osgi/issues/50
https://vaadin.com/security/cve-2021-31407
https://github.com/vaadin/flow/pull/10229
https://github.com/vaadin/flow/pull/10269
https://github.com/vaadin/osgi/issues/50
https://vaadin.com/security/cve-2021-31407
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
8.6 · High
Information
Source identifier
Vulnerability status
Modified
Published
2021-04-23T14:15:08.767Z
4 years agoLast modified
2024-11-21T05:05:36.100Z
1 year ago