CVE-2023-25500
Summary
| CVE | CVE-2023-25500 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-06-22 13:15:00 UTC |
| Updated | 2023-06-30 16:32:00 UTC |
| Description | Possible information disclosure in Vaadin 10.0.0 to 10.0.23, 11.0.0 to 14.10.1, 15.0.0 to 22.0.28, 23.0.0 to 23.3.13, 24.0.0 to 24.0.6, 24.1.0.alpha1 to 24.1.0.rc2, resulting in potential information disclosure of class and method names in RPC responses by sending modified requests. |
Risk And Classification
Problem Types: CWE-200
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Vaadin | Vaadin | All | All | All | All |
| Application | Vaadin | Vaadin | 24.1.0 | alpha1 | All | All |
| Application | Vaadin | Vaadin | 24.1.0 | alpha2 | All | All |
| Application | Vaadin | Vaadin | 24.1.0 | alpha3 | All | All |
| Application | Vaadin | Vaadin | 24.1.0 | alpha4 | All | All |
| Application | Vaadin | Vaadin | 24.1.0 | alpha5 | All | All |
| Application | Vaadin | Vaadin | 24.1.0 | alpha6 | All | All |
| Application | Vaadin | Vaadin | 24.1.0 | beta1 | All | All |
| Application | Vaadin | Vaadin | 24.1.0 | beta2 | All | All |
| Application | Vaadin | Vaadin | 24.1.0 | beta3 | All | All |
| Application | Vaadin | Vaadin | 24.1.0 | rc1 | All | All |
| Application | Vaadin | Vaadin | 24.1.0 | rc2 | All | All |
| Application | Vaadin | Vaadin | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| fix: log error messages by caalador · Pull Request #16935 · vaadin/flow · GitHub | MISC | github.com | |
| CVE-2023-25500: Possible information disclosure of class and method names in RPC response | MISC | vaadin.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.