The default configuration of a TreeGrid component uses Object::toString as a key on the client-side and server communication in Vaadin 14.8.5 through 14.8.9, 22.0.6 through 22.0.14, 23.0.0.beta2 through 23.0.8 and 23.1.0.alpha1 through 23.1.0.alpha4, resulting in potential information disclosure of values that should not be available on the client-side.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-4962 | The default configuration of a TreeGrid component uses Object::toString as a key on the client-side and server communication in Vaadin 14.8.5 through 14.8.9, 22.0.6 through 22.0.14, 23.0.0.beta2 through 23.0.8 and 23.1.0.alpha1 through 23.1.0.alpha4, resulting in potential information disclosure of values that should not be available on the client-side. |
Github GHSA |
GHSA-qfr3-323w-qv27 | Possible information disclosure inside TreeGrid component with default data provider |
Fixes
Solution
No solution given by the vendor.
Workaround
User might define either: custom `toString()` or `getId()` in their entity.
References
History
No history.
Status: PUBLISHED
Assigner: Vaadin
Published:
Updated: 2024-09-16T18:09:13.978Z
Reserved: 2022-04-21T00:00:00
Link: CVE-2022-29567
No data.
Status : Modified
Published: 2022-05-24T15:15:08.220
Modified: 2024-11-21T06:59:20.067
Link: CVE-2022-29567
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA