QID 982710
QID 982710: Java (maven) Security Update for com.vaadin:vaadin-server (GHSA-42j4-733x-5vcf)
Unsafe validation RegEx in `EmailValidator` class in `com.vaadin:vaadin-server` versions 7.0.0 through 7.7.21 (Vaadin 7.0.0 through 7.7.21) allows attackers to cause uncontrolled resource consumption by submitting malicious email addresses.
- https://vaadin.com/security/cve-2020-36320
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-42j4-733x-5vcf for updates pertaining to this vulnerability.
Vendor References
- GHSA-42j4-733x-5vcf -
github.com/advisories/GHSA-42j4-733x-5vcf
CVEs related to QID 982710
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-42j4-733x-5vcf | com.vaadin:vaadin-bom |
|
|
| GHSA-42j4-733x-5vcf | com.vaadin:vaadin-server |
|