Vulnerabilities > Vaadin > Flow > Low

DATE CVE VULNERABILITY TITLE RISK
2021-04-23 CVE-2021-31408 Insufficient Session Expiration vulnerability in Vaadin Flow and Vaadin
Authentication.logout() helper in com.vaadin:flow-client versions 5.0.0 prior to 6.0.0 (Vaadin 18), and 6.0.0 through 6.0.4 (Vaadin 19.0.0 through 19.0.3) uses incorrect HTTP method, which, in combination with Spring Security CSRF protection, allows local attackers to access Fusion endpoints after the user attempted to log out.
local
vaadin CWE-613
3.3
2021-04-23 CVE-2020-36319 Exposure of Resource to Wrong Sphere vulnerability in Vaadin Flow and Vaadin
Insecure configuration of default ObjectMapper in com.vaadin:flow-server versions 3.0.0 through 3.0.5 (Vaadin 15.0.0 through 15.0.4) may expose sensitive data if the application also uses e.g.
network
vaadin CWE-668
3.5
2021-04-23 CVE-2021-31406 Information Exposure Through Discrepancy vulnerability in Vaadin Flow and Vaadin
Non-constant-time comparison of CSRF tokens in endpoint request handler in com.vaadin:flow-server versions 3.0.0 through 5.0.3 (Vaadin 15.0.0 through 18.0.6), and com.vaadin:fusion-endpoint version 6.0.0 (Vaadin 19.0.0) allows attacker to guess a security token for Fusion endpoints via timing attack.
local
vaadin CWE-203
1.9
2021-04-23 CVE-2021-31404 Information Exposure Through Discrepancy vulnerability in Vaadin Flow and Vaadin
Non-constant-time comparison of CSRF tokens in UIDL request handler in com.vaadin:flow-server versions 1.0.0 through 1.0.13 (Vaadin 10.0.0 through 10.0.16), 1.1.0 prior to 2.0.0 (Vaadin 11 prior to 14), 2.0.0 through 2.4.6 (Vaadin 14.0.0 through 14.4.6), 3.0.0 prior to 5.0.0 (Vaadin 15 prior to 18), and 5.0.0 through 5.0.2 (Vaadin 18.0.0 through 18.0.5) allows attacker to guess a security token via timing attack.
local
vaadin CWE-203
1.9