QID 982667
QID 982667: Java (maven) Security Update for com.vaadin:vaadin-server (GHSA-q74r-4xw3-ppx9)
Missing variable sanitization in `Grid` component in `com.vaadin:vaadin-server` versions 7.4.0 through 7.7.19 (Vaadin 7.4.0 through 7.7.19), and 8.0.0 through 8.8.4 (Vaadin 8.0.0 through 8.8.4) allows attacker to inject malicious JavaScript via unspecified vector.
- https://vaadin.com/security/cve-2019-25028
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-q74r-4xw3-ppx9 for updates pertaining to this vulnerability.
Vendor References
- GHSA-q74r-4xw3-ppx9 -
github.com/advisories/GHSA-q74r-4xw3-ppx9
CVEs related to QID 982667
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-q74r-4xw3-ppx9 | com.vaadin:vaadin-bom |
|
|
| GHSA-q74r-4xw3-ppx9 | com.vaadin:vaadin-server |
|