Information Exposure Affecting com.vaadin:flow-server package, versions [1.0.0,1.0.20) [1.1.0,2.8.10) [3.0.0,9.1.1) [23.0.0,23.3.11) [24.0.0,24.0.8) [24.1.0.alpha1,24.1.0)
Threat Intelligence
EPSS
0.07% (31st
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-JAVA-COMVAADIN-5734222
- published 23 Jun 2023
- disclosed 22 Jun 2023
- credit Kim Leppänen
Introduced: 22 Jun 2023
CVE-2023-25499 Open this link in a new tabHow to fix?
Upgrade com.vaadin:flow-server
to version 1.0.20, 2.8.10, 9.1.1, 23.3.11, 24.0.8, 24.1.0 or higher.
Overview
Affected versions of this package are vulnerable to Information Exposure when adding non-visible components to the UI in the server side.
CVSS Scores
version 3.1