GHSA-c332-w4jm-55wv
Dashboard / Vulnerabilities / GHSA-c332-w4jm-55wv
Summary: Regular expression Denial of Service (ReDoS) in EmailValidator class in V7 compatibility module in Vaadin 8
Details: Unsafe validation RegEx in `EmailValidator` component in `com.vaadin:vaadin-compatibility-server` versions 8.0.0 through 8.12.4 (Vaadin versions 8.0.0 through 8.12.4) allows attackers to cause uncontrolled resource consumption by submitting malicious email addresses.
References: https://github.com/vaadin/framework/security/advisories/GHSA-c332-w4jm-55wv, https://nvd.nist.gov/vuln/detail/CVE-2021-31409, https://github.com/vaadin/framework/issues/12240, https://github.com/vaadin/framework/pull/12241, https://vaadin.com/security/cve-2021-31409
Affected packages
Package
Name: com.vaadin:vaadin-compatibility-server
Purl: pkg:maven/com.vaadin/vaadin-compatibility-server
Affected ranges
Type: ECOSYSTEM
Events:
