Record summary

CVE-2021-31411 has a selected CVSS score of 6.3 (medium).

Description

Insecure temporary directory usage in frontend build functionality of com.vaadin:flow-server versions 2.0.9 through 2.5.2 (Vaadin 14.0.3 through Vaadin 14.5.2), 3.0 prior to 6.0 (Vaadin 15 prior to 19), and 6.0.0 through 6.0.5 (Vaadin 19.0.0 through 19.0.4) allows local users to inject malicious code into frontend resources during application rebuilds.

Description source: CVE List

Affected products and versions

3
ProductSourceVersion rangeStatus
CVE List14.0.3 to < *affected
CVE List2.0.9 to < *affected
GitHub Advisory14.0.3 to < 14.5.3 · Fixed in 14.5.3affected
15.0.0 to < 19.0.5 · Fixed in 19.0.5affected

References

4