Missing output sanitization in default RouteNotFoundError view in com.vaadin:flow-server versions 1.0.0 through 1.0.10 (Vaadin 10.0.0 through 10.0.13), and 1.1.0 through 1.4.2 (Vaadin 11.0.0 through 13.0.5) allows attacker to execute malicious JavaScript via crafted URL
Advisories
Source ID Title
EUVD EUVD EUVD-2021-0873 Missing output sanitization in default RouteNotFoundError view in com.vaadin:flow-server versions 1.0.0 through 1.0.10 (Vaadin 10.0.0 through 10.0.13), and 1.1.0 through 1.4.2 (Vaadin 11.0.0 through 13.0.5) allows attacker to execute malicious JavaScript via crafted URL
Github GHSA Github GHSA GHSA-rp4x-wxqv-cf9m Reflected cross-site scripting in default RouteNotFoundError view in Vaadin 10 and 11-13
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Vaadin

Published:

Updated: 2024-09-17T01:15:38.495Z

Reserved: 2021-04-13T00:00:00

Link: CVE-2019-25027

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-04-23T16:15:07.987

Modified: 2024-11-21T04:39:46.430

Link: CVE-2019-25027

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.