QID 982708
QID 982708: Java (maven) Security Update for com.vaadin:flow-server (GHSA-jmx8-355m-8vwh)
Missing check in UIDL request handler in com.vaadin:flow-server versions 1.0.0 through 1.0.5 (Vaadin 10.0.0 through 10.0.7, and 11.0.0 through 11.0.2) allows attacker to update element property values via crafted synchronization message.
- https://vaadin.com/security/cve-2018-25007
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-jmx8-355m-8vwh for updates pertaining to this vulnerability.
Vendor References
- GHSA-jmx8-355m-8vwh -
github.com/advisories/GHSA-jmx8-355m-8vwh
CVEs related to QID 982708
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-jmx8-355m-8vwh | com.vaadin:flow-server |
|