Description
Missing check in UIDL request handler in com.vaadin:flow-server versions 1.0.0 through 1.0.5 (Vaadin 10.0.0 through 10.0.7, and 11.0.0 through 11.0.2) allows attacker to update element property values via crafted synchronization message.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-0842 | Missing check in UIDL request handler in com.vaadin:flow-server versions 1.0.0 through 1.0.5 (Vaadin 10.0.0 through 10.0.7, and 11.0.0 through 11.0.2) allows attacker to update element property values via crafted synchronization message. |
Github GHSA |
GHSA-jmx8-355m-8vwh | Unauthorized client-side property update in UIDL request handler in Vaadin 10 and 11 |
References
History
No history.
Status: PUBLISHED
Assigner: Vaadin
Published:
Updated: 2024-09-16T18:18:49.023Z
Reserved: 2021-04-13T00:00:00.000Z
Link: CVE-2018-25007
No data.
Status : Modified
Published: 2021-04-23T16:15:07.933
Modified: 2024-11-21T04:03:20.533
Link: CVE-2018-25007
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA