Improper URL validation in development mode handler in com.vaadin:flow-server versions 2.0.0 through 2.4.1 (Vaadin 14.0.0 through 14.4.2), and 3.0 prior to 5.0 (Vaadin 15 prior to 18) allows attacker to request arbitrary files stored outside of intended frontend resources folder.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Vaadin

Published: 2021-04-23T16:05:40.889444Z

Updated: 2024-09-17T00:45:59.853Z

Reserved: 2021-04-13T00:00:00

Link: CVE-2020-36321

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2021-04-23T16:15:08.403

Modified: 2021-05-05T17:26:01.250

Link: CVE-2020-36321

cve-icon Redhat

No data.