[MAVEN:GHSA-RJWW-2X8V-M9V9] Potential sensitive data exposure in applications using Vaadin 15

Severity Low
Affected Packages 1
Fixed Packages 1
CVEs 1

Insecure configuration of default ObjectMapper in com.vaadin:flow-server versions 3.0.0 through 3.0.5 (Vaadin 15.0.0 through 15.0.4) may expose sensitive data if the application also uses e.g. @RestController

Package Affected Version
pkg:maven/com.vaadin/flow-server >= 3.0.0, < 3.0.6
Package Fixed Version
pkg:maven/com.vaadin/flow-server = 3.0.6
ID
MAVEN:GHSA-RJWW-2X8V-M9V9
Severity
low
URL
https://github.com/advisories/GHSA-rjww-2x8v-m9v9
Published
2021-04-19T14:52:14
(3 years ago)
Modified
2023-01-29T05:05:26
(19 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/com.vaadin/flow-server com.vaadin flow-server >= 3.0.0 < 3.0.6
Fixed pkg:maven/com.vaadin/flow-server com.vaadin flow-server = 3.0.6
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...