GHSA-25xc-jwfq-39jw
Dashboard / Vulnerabilities / GHSA-25xc-jwfq-39jw
Summary: OSGi applications using Vaadin 12-14 and 19 vulnerable to server classes and resources exposure
Details: Vulnerability in OSGi integration in `com.vaadin:flow-server` versions 1.2.0 through 2.4.7 (Vaadin 12.0.0 through 14.4.9), and 6.0.0 through 6.0.1 (Vaadin 19.0.0) allows attacker to access application classes and resources on the server via crafted HTTP request. - https://vaadin.com/security/cve-2021-31407
References: https://github.com/vaadin/flow/security/advisories/GHSA-25xc-jwfq-39jw, https://nvd.nist.gov/vuln/detail/CVE-2021-31407, https://github.com/vaadin/osgi/issues/50, https://github.com/vaadin/flow/pull/10229, https://github.com/vaadin/flow/pull/10269, https://github.com/vaadin/flow, https://vaadin.com/security/cve-2021-31407
Affected packages
Package
Name: com.vaadin:flow-server
Purl: pkg:maven/com.vaadin/flow-server
Affected ranges
Type: ECOSYSTEM
Events:
