Insecure configuration of default ObjectMapper in com.vaadin:flow-server versions 3.0.0 through 3.0.5 (Vaadin 15.0.0 through 15.0.4) may expose sensitive data if the application also uses e.g. @RestController
Advisories
Source ID Title
EUVD EUVD EUVD-2021-0872 Insecure configuration of default ObjectMapper in com.vaadin:flow-server versions 3.0.0 through 3.0.5 (Vaadin 15.0.0 through 15.0.4) may expose sensitive data if the application also uses e.g. @RestController
Github GHSA Github GHSA GHSA-rjww-2x8v-m9v9 Potential sensitive data exposure in applications using Vaadin 15
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Vaadin

Published:

Updated: 2024-09-16T23:45:49.973Z

Reserved: 2021-04-13T00:00:00

Link: CVE-2020-36319

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-04-23T16:15:08.317

Modified: 2024-11-21T05:29:16.027

Link: CVE-2020-36319

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses