QID 982687

QID 982687: Java (maven) Security Update for com.vaadin:vaadin-bom (GHSA-mr8h-j9cv-4m8h)

`Authentication.logout()` helper in `com.vaadin:flow-client` versions 5.0.0 prior to 6.0.0 (Vaadin 18), and 6.0.0 through 6.0.4 (Vaadin 19.0.0 through 19.0.3) uses incorrect HTTP method, which, in combination with Spring Security CSRF protection, allows local attackers to access Fusion endpoints after the user attempted to log out.

- https://vaadin.com/security/cve-2021-31408

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as High - 7.1 severity.
  • CVSS V2 rated as Medium - 3.3 severity.
  • Solution
    Customers are advised to refer to GHSA-mr8h-j9cv-4m8h for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 982687

    Software Advisories
    Advisory ID Software Component Link
    GHSA-mr8h-j9cv-4m8h com.vaadin:vaadin-bom URL Logo github.com/advisories/GHSA-mr8h-j9cv-4m8h