Debug Messages Revealing Unnecessary Information Affecting com.vaadin:vaadin package, versions [10.0.0,10.0.24)[11.0.0,14.10.2)[15.0.0,22.1.0)[23.0.0,23.3.14)[24.0.0,24.0.7)[24.1.0.alpha1,24.1.0)


Severity

Recommended
0.0
low
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.07% (32nd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-COMVAADIN-5734224
  • published23 Jun 2023
  • disclosed22 Jun 2023
  • creditUnknown

Introduced: 22 Jun 2023

CVE-2023-25500  (opens in a new tab)
CWE-1295  (opens in a new tab)

How to fix?

Upgrade com.vaadin:vaadin to version 10.0.24, 14.10.2, 22.1.0, 23.3.14, 24.0.7, 24.1.0 or higher.

Overview

com.vaadin:vaadin is a Java framework for modern Java web applications.

Affected versions of this package are vulnerable to Debug Messages Revealing Unnecessary Information in rpc/PublishedServerEventHandlerRpcHandler.java. Class and method names can be included in RPC responses when processing modified requests.

CVSS Scores

version 3.1