CVE-2021-31407
HIGHcom.vaadin:flow-server <2.4.7, Vaadin <14.4.9 - RCE
Title source: llmDescription
Vulnerability in OSGi integration in com.vaadin:flow-server versions 1.2.0 through 2.4.7 (Vaadin 12.0.0 through 14.4.9), and 6.0.0 through 6.0.1 (Vaadin 19.0.0) allows attacker to access application classes and resources on the server via crafted HTTP request.
Scores
CVSS v3
8.6
EPSS
0.0180
EPSS Percentile
82.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Classification
CWE
CWE-668
CWE-402
Status
published
Affected Products (4)
vaadin/flow
< 2.4.8
vaadin/vaadin
< 14.4.10
vaadin/vaadin
com.vaadin/flow-server
< 2.4.8Maven
Timeline
Published
Apr 23, 2021
Tracked Since
Feb 18, 2026