CVE-2021-33604
URL encoding error in development mode handler in com.vaadin:flow-server versions 2.0.0 through 2.6.1 (Vaadin 14.0.0 through 14.6.1), 3.0.0 through 6.0.9 (Vaadin 15.0.0 through 19.0.8) allows local user to execute arbitrary JavaScript code by opening…
Does this matter?
Lower severity and a low EPSS score (0.29%). Track it; it rarely justifies an emergency change on its own.
Description
URL encoding error in development mode handler in com.vaadin:flow-server versions 2.0.0 through 2.6.1 (Vaadin 14.0.0 through 14.6.1), 3.0.0 through 6.0.9 (Vaadin 15.0.0 through 19.0.8) allows local user to execute arbitrary JavaScript code by opening crafted URL in browser.
- CVSS 3.1
- 2.5 LOWCVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N
- EPSS
- 0.29% probability · 21th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-172
- Affected
- vaadin/flow-server · vaadin/vaadin
- Source
- security@vaadin.com
References
- https://github.com/vaadin/flow/pull/11099Patch, Third Party Advisory
- https://vaadin.com/security/cve-2021-33604Vendor Advisory
- https://github.com/vaadin/flow/pull/11099Patch, Third Party Advisory
- https://vaadin.com/security/cve-2021-33604Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.