Description
Authentication.logout() helper in com.vaadin:flow-client versions 5.0.0 prior to 6.0.0 (Vaadin 18), and 6.0.0 through 6.0.4 (Vaadin 19.0.0 through 19.0.3) uses incorrect HTTP method, which, in combination with Spring Security CSRF protection, allows local attackers to access Fusion endpoints after the user attempted to log out.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-0848 | Authentication.logout() helper in com.vaadin:flow-client versions 5.0.0 prior to 6.0.0 (Vaadin 18), and 6.0.0 through 6.0.4 (Vaadin 19.0.0 through 19.0.3) uses incorrect HTTP method, which, in combination with Spring Security CSRF protection, allows local attackers to access Fusion endpoints after the user attempted to log out. |
Github GHSA |
GHSA-mr8h-j9cv-4m8h | Server session is not invalidated when logout() helper method of Authentication module is used in Vaadin 18-19 |
References
History
No history.
Status: PUBLISHED
Assigner: Vaadin
Published:
Updated: 2024-09-17T02:06:19.701Z
Reserved: 2021-04-15T00:00:00.000Z
Link: CVE-2021-31408
No data.
Status : Modified
Published: 2021-04-23T17:15:08.260
Modified: 2024-11-21T06:05:36.240
Link: CVE-2021-31408
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA