Possible information disclosure in Vaadin 10.0.0 to 10.0.23, 11.0.0 to 14.10.1, 15.0.0 to 22.0.28, 23.0.0 to 23.3.13, 24.0.0 to 24.0.6, 24.1.0.alpha1 to 24.1.0.rc2, resulting in potential information disclosure of class and method names in RPC responses by sending modified requests.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-1775 | Possible information disclosure in Vaadin 10.0.0 to 10.0.23, 11.0.0 to 14.10.1, 15.0.0 to 22.0.28, 23.0.0 to 23.3.13, 24.0.0 to 24.0.6, 24.1.0.alpha1 to 24.1.0.rc2, resulting in potential information disclosure of class and method names in RPC responses by sending modified requests. |
Github GHSA |
GHSA-ch48-9r3q-pv7x | Vaadin vulnerable to possible information disclosure of class and method names in RPC response |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 05 Dec 2024 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Vaadin
Published:
Updated: 2024-12-05T19:59:30.912Z
Reserved: 2023-02-06T20:44:44.569Z
Link: CVE-2023-25500
Updated: 2024-08-02T11:25:18.633Z
Status : Modified
Published: 2023-06-22T13:15:09.737
Modified: 2024-11-21T07:49:37.627
Link: CVE-2023-25500
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA