QID 982539
QID 982539: Java (maven) Security Update for com.vaadin:vaadin-bom (GHSA-p826-8vhq-h439)
Insecure temporary directory usage in frontend build functionality of `com.vaadin:flow-server` versions 2.0.9 through 2.5.2 (Vaadin 14.0.3 through Vaadin 14.5.2), 3.0 prior to 6.0 (Vaadin 15 prior to 19), and 6.0.0 through 6.0.5 (Vaadin 19.0.0 through 19.0.4) allows local users to inject malicious code into frontend resources during application rebuilds.
- https://vaadin.com/security/cve-2021-31411
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-p826-8vhq-h439 for updates pertaining to this vulnerability.
Vendor References
- GHSA-p826-8vhq-h439 -
github.com/advisories/GHSA-p826-8vhq-h439
CVEs related to QID 982539
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-p826-8vhq-h439 | com.vaadin:vaadin-bom |
|