GHSA-2wqp-jmcc-mc77
Dashboard / Vulnerabilities / GHSA-2wqp-jmcc-mc77
Summary: Regular expression denial of service (ReDoS) in EmailField component in Vaadin 14 and 15-17
Details: Unsafe validation RegEx in `EmailField` component in `com.vaadin:vaadin-text-field-flow` versions 2.0.4 through 2.3.2 (Vaadin 14.0.6 through 14.4.3), and 3.0.0 through 4.0.2 (Vaadin 15.0.0 through 17.0.10) allows attackers to cause uncontrolled resource consumption by submitting malicious email addresses. - https://vaadin.com/security/cve-2021-31405
References: https://github.com/vaadin/platform/security/advisories/GHSA-2wqp-jmcc-mc77, https://nvd.nist.gov/vuln/detail/CVE-2021-31405, https://github.com/vaadin/flow-components/pull/442, https://vaadin.com/security/cve-2021-31405
Affected packages
Package
Name: com.vaadin:vaadin-bom
Purl: pkg:maven/com.vaadin/vaadin-bom
Affected ranges
Type: ECOSYSTEM
Events:
