CVE-2021-31411
Summary
| CVE | CVE-2021-31411 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-05-05 19:15:00 UTC |
| Updated | 2021-05-18 14:01:00 UTC |
| Description | Insecure temporary directory usage in frontend build functionality of com.vaadin:flow-server versions 2.0.9 through 2.5.2 (Vaadin 14.0.3 through Vaadin 14.5.2), 3.0 prior to 6.0 (Vaadin 15 prior to 19), and 6.0.0 through 6.0.5 (Vaadin 19.0.0 through 19.0.4) allows local users to inject malicious code into frontend resources during application rebuilds. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CVE-2021-31411: Insecure temporary directory usage in frontend build functionality of Vaadin 14 and 15-19 | CONFIRM | vaadin.com | |
| fix: Compare file content from stream by caalador · Pull Request #10640 · vaadin/flow · GitHub | CONFIRM | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 982539 Java (maven) Security Update for com.vaadin:vaadin-bom (GHSA-p826-8vhq-h439)