OSGi applications using Vaadin 12-14 and 19 vulnerable to server classes and resources exposure
Package
Affected versions
= 6.0.0
>= 1.2.0, <= 2.4.7
Patched versions
6.0.1
2.4.8
Description
Reviewed
Apr 16, 2021
Published to the GitHub Advisory Database
Apr 19, 2021
Published by the National Vulnerability Database
Apr 23, 2021
Last updated
Jan 27, 2023
Vulnerability in OSGi integration in
com.vaadin:flow-server
versions 1.2.0 through 2.4.7 (Vaadin 12.0.0 through 14.4.9), and 6.0.0 through 6.0.1 (Vaadin 19.0.0) allows attacker to access application classes and resources on the server via crafted HTTP request.References