Record summary

CVE-2019-25027 has a selected CVSS score of 6.1 (medium).

Description

Missing output sanitization in default RouteNotFoundError view in com.vaadin:flow-server versions 1.0.0 through 1.0.10 (Vaadin 10.0.0 through 10.0.13), and 1.1.0 through 1.4.2 (Vaadin 11.0.0 through 13.0.5) allows attacker to execute malicious JavaScript via crafted URL

Description source: CVE List

Affected products and versions

3
ProductSourceVersion rangeStatus
CVE List10.0.0 to < *affected
CVE List1.0.0 to < *affected
GitHub Advisory1.0.0 to < 1.0.11 · Fixed in 1.0.11affected
1.1.0 to < 1.4.3 · Fixed in 1.4.3affected

References

4