Description
The default configuration of a TreeGrid component uses Object::toString as a key on the client-side and server communication in Vaadin 14.8.5 through 14.8.9, 22.0.6 through 22.0.14, 23.0.0.beta2 through 23.0.8 and 23.1.0.alpha1 through 23.1.0.alpha4, resulting in potential information disclosure of values that should not be available on the client-side.
No analysis available yet.
Remediation
Vendor Workaround
User might define either: custom `toString()` or `getId()` in their entity.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-4962 | The default configuration of a TreeGrid component uses Object::toString as a key on the client-side and server communication in Vaadin 14.8.5 through 14.8.9, 22.0.6 through 22.0.14, 23.0.0.beta2 through 23.0.8 and 23.1.0.alpha1 through 23.1.0.alpha4, resulting in potential information disclosure of values that should not be available on the client-side. |
Github GHSA |
GHSA-qfr3-323w-qv27 | Possible information disclosure inside TreeGrid component with default data provider |
References
History
No history.
Status: PUBLISHED
Assigner: Vaadin
Published:
Updated: 2024-09-16T18:09:13.978Z
Reserved: 2022-04-21T00:00:00.000Z
Link: CVE-2022-29567
No data.
Status : Modified
Published: 2022-05-24T15:15:08.220
Modified: 2024-11-21T06:59:20.067
Link: CVE-2022-29567
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA