CVE-2023-25499
MEDIUMVaadin 10.0.0-24.1.0.beta1 - Information Disclosure via Non-Visible Component Rendering
Title source: llmDescription
When adding non-visible components to the UI in server side, content is sent to the browser in Vaadin 10.0.0 through 10.0.22, 11.0.0 through 14.10.0, 15.0.0 through 22.0.28, 23.0.0 through 23.3.12, 24.0.0 through 24.0.5 and 24.1.0.alpha1 to 24.1.0.beta1, resulting in potential information disclosure.
References (2)
Core 2
Core References
Vendor Advisory
https://vaadin.com/security/CVE-2023-25499
Scores
CVSS v3
5.7
EPSS
0.0058
EPSS Percentile
43.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-200
Status
published
Products (4)
com.vaadin/flow-server
1.0.0 - 1.0.20Maven
com.vaadin/vaadin
10.0.0 - 10.0.23Maven
vaadin/vaadin
24.1.0 alpha1 (7 CPE variants)
vaadin/vaadin
10.0.0 - 10.0.23
Published
Jun 22, 2023
Tracked Since
Feb 18, 2026