QID 982668
QID 982668: Java (maven) Security Update for com.vaadin:flow-server (GHSA-rp4x-wxqv-cf9m)
Missing output sanitization in default `RouteNotFoundError` view in `com.vaadin:flow-server` versions 1.0.0 through 1.0.10 (Vaadin 10.0.0 through 10.0.13), and 1.1.0 through 1.4.2 (Vaadin 11.0.0 through 13.0.5) allows attacker to execute malicious JavaScript via crafted URL.
- https://vaadin.com/security/cve-2019-25027
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-rp4x-wxqv-cf9m for updates pertaining to this vulnerability.
Vendor References
- GHSA-rp4x-wxqv-cf9m -
github.com/advisories/GHSA-rp4x-wxqv-cf9m
CVEs related to QID 982668
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-rp4x-wxqv-cf9m | com.vaadin:flow-server |
|