The default configuration of a TreeGrid component uses Object::toString as a key on the client-side and server communication in Vaadin 14.8.5 through 14.8.9, 22.0.6 through 22.0.14, 23.0.0.beta2 through 23.0.8 and 23.1.0.alpha1 through 23.1.0.alpha4, resulting in potential information disclosure of values that should not be available on the client-side.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: Vaadin
Published: 2022-05-24T14:20:19.452600Z
Updated: 2024-09-16T18:09:13.978Z
Reserved: 2022-04-21T00:00:00
Link: CVE-2022-29567
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-05-24T15:15:08.220
Modified: 2024-11-21T06:59:20.067
Link: CVE-2022-29567
Redhat
No data.