Beveiligingsadvies

CVE-2021-33604

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2021-06-24 11:16:27
Laatst bijgewerkt 2024-09-17 03:13:22
Toegewezen door Vaadin
CVSS-score 2.5
Status PUBLISHED

Beschrijving

URL encoding error in development mode handler in com.vaadin:flow-server versions 2.0.0 through 2.6.1 (Vaadin 14.0.0 through 14.6.1), 3.0.0 through 6.0.9 (Vaadin 15.0.0 through 19.0.8) allows local user to execute arbitrary JavaScript code by opening crafted URL in browser.