SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-33604

URL encoding error in development mode handler in com.vaadin:flow-server versions 2.0.0 through 2.6.1 (Vaadin 14.0.0 through 14.6.1), 3.0.0 through 6.0.9 (Vaadin 15.0.0 through 19.0.8) allows local user to execute arbitrary JavaScript code by opening…

LOW 2.5EPSS 0.29%

Does this matter?

Lower severity and a low EPSS score (0.29%). Track it; it rarely justifies an emergency change on its own.

Description

URL encoding error in development mode handler in com.vaadin:flow-server versions 2.0.0 through 2.6.1 (Vaadin 14.0.0 through 14.6.1), 3.0.0 through 6.0.9 (Vaadin 15.0.0 through 19.0.8) allows local user to execute arbitrary JavaScript code by opening crafted URL in browser.

CVSS 3.1
2.5 LOWCVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N
EPSS
0.29% probability · 21th percentile
CISA KEV
Not listed
Weakness
CWE-172
Affected
vaadin/flow-server · vaadin/vaadin
Source
security@vaadin.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.