com.vaadin:vaadin-server@8.14.5

  • latest version

    8.32.0

  • latest non vulnerable version

  • first published

    13 years ago

  • latest version published

    6 days ago

  • licenses detected

  • package registry

  • Direct Vulnerabilities

    Known vulnerabilities in the com.vaadin:vaadin-server package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Cross-site Scripting (XSS)

    com.vaadin:vaadin-server is a Java framework for modern Java web applications.

    Affected versions of this package are vulnerable to Cross-site Scripting (XSS) in the ContextMenuManager and Action classed, when handling Action captions. An attacker can cause scripts to be executed by injecting them into captions.

    Note: As of version 23, the Action class is only used by the Spreadsheet component.

    How to fix Cross-site Scripting (XSS)?

    Upgrade com.vaadin:vaadin-server to version 7.7.50, 8.30.0 or higher.

    [7.0.0,7.7.50)[8.0.0,8.30.0)
    • M
    Arbitrary File Upload

    com.vaadin:vaadin-server is a Java framework for modern Java web applications.

    Affected versions of this package are vulnerable to Arbitrary File Upload via Vaadin Upload's start listener in the multi-upload mode. An attacker can upload unauthorized files by bypassing server-side metadata validation.

    How to fix Arbitrary File Upload?

    Upgrade com.vaadin:vaadin-server to version 7.7.48, 8.28.2 or higher.

    [7.0.0,7.7.48)[8.0.0,8.28.2)