Vulnerabilities > Vaadin > Flow > High

DATE CVE VULNERABILITY TITLE RISK
2021-05-05 CVE-2021-31411 Unspecified vulnerability in Vaadin Flow
Insecure temporary directory usage in frontend build functionality of com.vaadin:flow-server versions 2.0.9 through 2.5.2 (Vaadin 14.0.3 through Vaadin 14.5.2), 3.0 prior to 6.0 (Vaadin 15 prior to 19), and 6.0.0 through 6.0.5 (Vaadin 19.0.0 through 19.0.4) allows local users to inject malicious code into frontend resources during application rebuilds.
local
low complexity
vaadin
7.8
2021-04-23 CVE-2021-31408 Insufficient Session Expiration vulnerability in Vaadin Flow and Vaadin
Authentication.logout() helper in com.vaadin:flow-client versions 5.0.0 prior to 6.0.0 (Vaadin 18), and 6.0.0 through 6.0.4 (Vaadin 19.0.0 through 19.0.3) uses incorrect HTTP method, which, in combination with Spring Security CSRF protection, allows local attackers to access Fusion endpoints after the user attempted to log out.
local
low complexity
vaadin CWE-613
7.1
2021-04-23 CVE-2021-31407 Exposure of Resource to Wrong Sphere vulnerability in Vaadin Flow
Vulnerability in OSGi integration in com.vaadin:flow-server versions 1.2.0 through 2.4.7 (Vaadin 12.0.0 through 14.4.9), and 6.0.0 through 6.0.1 (Vaadin 19.0.0) allows attacker to access application classes and resources on the server via crafted HTTP request.
network
low complexity
vaadin CWE-668
7.5
2021-04-23 CVE-2021-31405 Resource Exhaustion vulnerability in Vaadin Flow
Unsafe validation RegEx in EmailField component in com.vaadin:vaadin-text-field-flow versions 2.0.4 through 2.3.2 (Vaadin 14.0.6 through 14.4.3), and 3.0.0 through 4.0.2 (Vaadin 15.0.0 through 17.0.10) allows attackers to cause uncontrolled resource consumption by submitting malicious email addresses.
network
low complexity
vaadin CWE-400
7.5
2021-04-23 CVE-2020-36321 Path Traversal vulnerability in Vaadin Flow
Improper URL validation in development mode handler in com.vaadin:flow-server versions 2.0.0 through 2.4.1 (Vaadin 14.0.0 through 14.4.2), and 3.0 prior to 5.0 (Vaadin 15 prior to 18) allows attacker to request arbitrary files stored outside of intended frontend resources folder.
network
low complexity
vaadin CWE-22
7.5