[MAVEN:GHSA-JFMF-W293-8XR8] Regular expression Denial of Service (ReDoS) in EmailValidator class in V7 compatibility module in Vaadin 8

Severity High
Affected Packages 1
Fixed Packages 1

Unsafe validation RegEx in EmailValidator component in com.vaadin:vaadin-compatibility-server versions 8.0.0 through 8.12.4 (Vaadin versions 8.0.0 through 8.12.4) allows attackers to cause uncontrolled resource consumption by submitting malicious email addresses.

Package Affected Version
pkg:maven/com.vaadin/vaadin-bom >= 8.0.0, <= 8.12.4
Package Fixed Version
pkg:maven/com.vaadin/vaadin-bom = 8.13.0
ID
MAVEN:GHSA-JFMF-W293-8XR8
Severity
high
URL
https://github.com/advisories/GHSA-jfmf-w293-8xr8
Published
2021-10-13T18:55:52
(2 years ago)
Modified
2023-01-09T05:05:03
(20 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/com.vaadin/vaadin-bom com.vaadin vaadin-bom >= 8.0.0 <= 8.12.4
Fixed pkg:maven/com.vaadin/vaadin-bom com.vaadin vaadin-bom = 8.13.0
Loading...