Insecure temporary directory usage in frontend build functionality of com.vaadin:flow-server versions 2.0.9 through 2.5.2 (Vaadin 14.0.3 through Vaadin 14.5.2), 3.0 prior to 6.0 (Vaadin 15 prior to 19), and 6.0.0 through 6.0.5 (Vaadin 19.0.0 through 19.0.4) allows local users to inject malicious code into frontend resources during application rebuilds.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-1147 | Insecure temporary directory usage in frontend build functionality of com.vaadin:flow-server versions 2.0.9 through 2.5.2 (Vaadin 14.0.3 through Vaadin 14.5.2), 3.0 prior to 6.0 (Vaadin 15 prior to 19), and 6.0.0 through 6.0.5 (Vaadin 19.0.0 through 19.0.4) allows local users to inject malicious code into frontend resources during application rebuilds. |
Github GHSA |
GHSA-p826-8vhq-h439 | Insecure temporary directory usage in frontend build functionality of Vaadin 14 and 15-19 |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: Vaadin
Published:
Updated: 2024-09-16T18:08:17.789Z
Reserved: 2021-04-15T00:00:00
Link: CVE-2021-31411
No data.
Status : Modified
Published: 2021-05-05T19:15:08.777
Modified: 2024-11-21T06:05:36.923
Link: CVE-2021-31411
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA