CVE-2021-31411

CVSS v3.1 7.8 (High)
78% Progress
CVSS v2.0 4.6 (Medium)
46% Progress
EPSS 0.04 % (5th)
0.04% Progress
Affected Products 2
Advisories 1

Insecure temporary directory usage in frontend build functionality of com.vaadin:flow-server versions 2.0.9 through 2.5.2 (Vaadin 14.0.3 through Vaadin 14.5.2), 3.0 prior to 6.0 (Vaadin 15 prior to 19), and 6.0.0 through 6.0.5 (Vaadin 19.0.0 through 19.0.4) allows local users to inject malicious code into frontend resources during application rebuilds.

Weaknesses
CWE-379
Creation of Temporary File in Directory with Insecure Permissions
CWE-NVD-Other
CVE Status
PUBLISHED
CNA
Vaadin Ltd.
Published Date
2021-05-05 19:15:08
(3 years ago)
Updated Date
2021-05-18 14:01:57
(3 years ago)

Affected Products

Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Vaadin Flow from 2.0.9 version and prior 2.5.3 version cpe:2.3:a:vaadin:flow >= 2.0.9 < 2.5.3
  Vaadin Flow from 3.0.0 version and 5.0.0 and prior versions cpe:2.3:a:vaadin:flow >= 3.0.0 <= 5.0.0
  Vaadin Flow from 6.0.0 version and 6.0.6 and prior versions cpe:2.3:a:vaadin:flow >= 6.0.0 <= 6.0.6
  Vaadin from 14.0.3 version and prior 14.5.3 version cpe:2.3:a:vaadin:vaadin >= 14.0.3 < 14.5.3
  Vaadin from 15.0.0 version and prior 19.0.5 version cpe:2.3:a:vaadin:vaadin >= 15.0.0 < 19.0.5
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...