Reflected cross-site scripting in development mode handler in Vaadin 14, 15-19
Package
Affected versions
>= 14.0.0, <= 14.6.1
>= 15.0.0, <= 19.0.8
Patched versions
14.6.2
19.0.9
Description
Published by the National Vulnerability Database
Jun 24, 2021
Reviewed
Jun 24, 2021
Published to the GitHub Advisory Database
Jun 28, 2021
Last updated
Feb 1, 2023
URL encoding error in development mode handler in
com.vaadin:flow-server
versions 2.0.0 through 2.6.1 (Vaadin 14.0.0 through 14.6.1), 3.0.0 through 6.0.9 (Vaadin 15.0.0 through 19.0.8) allows local user to execute arbitrary JavaScript code by opening crafted URL in browser.References