QID 982539

QID 982539: Java (maven) Security Update for com.vaadin:vaadin-bom (GHSA-p826-8vhq-h439)

Insecure temporary directory usage in frontend build functionality of `com.vaadin:flow-server` versions 2.0.9 through 2.5.2 (Vaadin 14.0.3 through Vaadin 14.5.2), 3.0 prior to 6.0 (Vaadin 15 prior to 19), and 6.0.0 through 6.0.5 (Vaadin 19.0.0 through 19.0.4) allows local users to inject malicious code into frontend resources during application rebuilds.

- https://vaadin.com/security/cve-2021-31411

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as Medium - 4.6 severity.
  • Solution
    Customers are advised to refer to GHSA-p826-8vhq-h439 for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 982539

    Software Advisories
    Advisory ID Software Component Link
    GHSA-p826-8vhq-h439 com.vaadin:vaadin-bom URL Logo github.com/advisories/GHSA-p826-8vhq-h439