Unsafe validation RegEx in EmailField component in com.vaadin:vaadin-text-field-flow versions 2.0.4 through 2.3.2 (Vaadin 14.0.6 through 14.4.3), and 3.0.0 through 4.0.2 (Vaadin 15.0.0 through 17.0.10) allows attackers to cause uncontrolled resource consumption by submitting malicious email addresses.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-0740 | Unsafe validation RegEx in EmailField component in com.vaadin:vaadin-text-field-flow versions 2.0.4 through 2.3.2 (Vaadin 14.0.6 through 14.4.3), and 3.0.0 through 4.0.2 (Vaadin 15.0.0 through 17.0.10) allows attackers to cause uncontrolled resource consumption by submitting malicious email addresses. |
Github GHSA |
GHSA-2wqp-jmcc-mc77 | Regular expression denial of service (ReDoS) in EmailField component in Vaadin 14 and 15-17 |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: Vaadin
Published:
Updated: 2024-09-17T02:32:47.630Z
Reserved: 2021-04-15T00:00:00
Link: CVE-2021-31405
No data.
Status : Modified
Published: 2021-04-23T16:15:08.687
Modified: 2024-11-21T06:05:35.860
Link: CVE-2021-31405
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA