GHSA-c99r-67x4-whj6
Dashboard / Vulnerabilities / GHSA-c99r-67x4-whj6
Summary: Reflected cross-site scripting in development mode handler in Vaadin 14, 15-19
Details: URL encoding error in development mode handler in `com.vaadin:flow-server` versions 2.0.0 through 2.6.1 (Vaadin 14.0.0 through 14.6.1), 3.0.0 through 6.0.9 (Vaadin 15.0.0 through 19.0.8) allows local user to execute arbitrary JavaScript code by opening crafted URL in browser. - https://vaadin.com/security/cve-2021-33604
References: https://github.com/vaadin/platform/security/advisories/GHSA-c99r-67x4-whj6, https://nvd.nist.gov/vuln/detail/CVE-2021-33604, https://github.com/vaadin/flow/pull/11099, https://github.com/vaadin/flow, https://vaadin.com/security/cve-2021-33604
Affected packages
Package
Name: com.vaadin:vaadin-bom
Purl: pkg:maven/com.vaadin/vaadin-bom
Affected ranges
Type: ECOSYSTEM
Events:
