QID 982709
QID 982709: Java (maven) Security Update for com.vaadin:flow-server (GHSA-rjww-2x8v-m9v9)
Insecure configuration of default `ObjectMapper` in `com.vaadin:flow-server` versions 3.0.0 through 3.0.5 (Vaadin 15.0.0 through 15.0.4) may expose sensitive data if the application also uses e.g. `@RestController`
- https://vaadin.com/security/cve-2020-36319
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-rjww-2x8v-m9v9 for updates pertaining to this vulnerability.
Vendor References
- GHSA-rjww-2x8v-m9v9 -
github.com/advisories/GHSA-rjww-2x8v-m9v9
CVEs related to QID 982709
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-rjww-2x8v-m9v9 | com.vaadin:flow-server |
|