QID 982669
QID 982669: Java (maven) Security Update for com.vaadin:flow-server (GHSA-25xc-jwfq-39jw)
Vulnerability in OSGi integration in `com.vaadin:flow-server` versions 1.2.0 through 2.4.7 (Vaadin 12.0.0 through 14.4.9), and 6.0.0 through 6.0.1 (Vaadin 19.0.0) allows attacker to access application classes and resources on the server via crafted HTTP request.
- https://vaadin.com/security/cve-2021-31407
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-25xc-jwfq-39jw for updates pertaining to this vulnerability.
Vendor References
- GHSA-25xc-jwfq-39jw -
github.com/advisories/GHSA-25xc-jwfq-39jw
CVEs related to QID 982669
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-25xc-jwfq-39jw | com.vaadin:flow-server |
|