CVE-2021-31407
Summary
| CVE | CVE-2021-31407 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-04-23 16:15:00 UTC |
| Updated | 2022-08-12 18:02:00 UTC |
| Description | Vulnerability in OSGi integration in com.vaadin:flow-server versions 1.2.0 through 2.4.7 (Vaadin 12.0.0 through 14.4.9), and 6.0.0 through 6.0.1 (Vaadin 19.0.0) allows attacker to access application classes and resources on the server via crafted HTTP request. |
Risk And Classification
Problem Types: CWE-668
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Vaadin OSGi applications should not expose relevant classpath content as static resources · Issue #50 · vaadin/osgi · GitHub | CONFIRM | github.com | |
| fix: avoid exposing ServletContext resources via StaticFileServer (#10261) by denis-anisimov · Pull Request #10269 · vaadin/flow · GitHub | CONFIRM | github.com | |
| CVE-2021-31407: Server classes and resources exposure in OSGi applications using Vaadin 12-14 and 19 | CONFIRM | vaadin.com | |
| refactor: use StaticFileHandler as a service by denis-anisimov · Pull Request #10229 · vaadin/flow · GitHub | CONFIRM | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 982669 Java (maven) Security Update for com.vaadin:flow-server (GHSA-25xc-jwfq-39jw)