Description
Insecure configuration of default ObjectMapper in com.vaadin:flow-server versions 3.0.0 through 3.0.5 (Vaadin 15.0.0 through 15.0.4) may expose sensitive data if the application also uses e.g. @RestController
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-0872 | Insecure configuration of default ObjectMapper in com.vaadin:flow-server versions 3.0.0 through 3.0.5 (Vaadin 15.0.0 through 15.0.4) may expose sensitive data if the application also uses e.g. @RestController |
Github GHSA |
GHSA-rjww-2x8v-m9v9 | Potential sensitive data exposure in applications using Vaadin 15 |
References
History
No history.
Status: PUBLISHED
Assigner: Vaadin
Published:
Updated: 2024-09-16T23:45:49.973Z
Reserved: 2021-04-13T00:00:00.000Z
Link: CVE-2020-36319
No data.
Status : Modified
Published: 2021-04-23T16:15:08.317
Modified: 2024-11-21T05:29:16.027
Link: CVE-2020-36319
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA