QID 982687
QID 982687: Java (maven) Security Update for com.vaadin:vaadin-bom (GHSA-mr8h-j9cv-4m8h)
`Authentication.logout()` helper in `com.vaadin:flow-client` versions 5.0.0 prior to 6.0.0 (Vaadin 18), and 6.0.0 through 6.0.4 (Vaadin 19.0.0 through 19.0.3) uses incorrect HTTP method, which, in combination with Spring Security CSRF protection, allows local attackers to access Fusion endpoints after the user attempted to log out.
- https://vaadin.com/security/cve-2021-31408
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-mr8h-j9cv-4m8h for updates pertaining to this vulnerability.
Vendor References
- GHSA-mr8h-j9cv-4m8h -
github.com/advisories/GHSA-mr8h-j9cv-4m8h
CVEs related to QID 982687
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-mr8h-j9cv-4m8h | com.vaadin:vaadin-bom |
|