github.com
https://github.com/vaadin/flow/pull/16935 CVE-2023-25500
LOW
Vaadin vulnerable to possible information disclosure of class and method names in RPC response
Record summary
CVE-2023-25500 has a selected CVSS score of 3.5 (low).
Description
Possible information disclosure in Vaadin 10.0.0 to 10.0.23, 11.0.0 to 14.10.1, 15.0.0 to 22.0.28, 23.0.0 to 23.3.13, 24.0.0 to 24.0.6, 24.1.0.alpha1 to 24.1.0.rc2, resulting in potential information disclosure of class and method names in RPC responses by sending modified requests.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 5, 2024 · Source: CVE List
Affected products and versions
4| Product | Source | Version range | Status |
|---|---|---|---|
flow-serverBrowse flow / flow-serverDefault status: unaffected | CVE List | 1.0.0 to ≤ 1.0.20 | affected |
| 1.1.0 to ≤ 2.9.2 | affected | ||
| 3.0.0 to ≤ 9.1.1 | affected | ||
| 23.0.0 to ≤ 23.3.12 | affected | ||
| 24.0.0 to ≤ 24.0.8 | affected | ||
| 24.1.0.alpha1 to ≤ 24.1.0.rc3 | affected | ||
vaadinBrowse vaadin / vaadinDefault status: unaffected | CVE List | 10.0.0 to ≤ 10.0.23 | affected |
| 11.0.0 to ≤ 14.10.1 | affected | ||
| 15.0.0 to ≤ 22.0.8 | affected | ||
| 23.0.0 to ≤ 23.3.13 | affected | ||
| 24.0.0 to ≤ 24.0.6 | affected | ||
| 24.1.0.alpha1 to ≤ 24.1.0.rc2 | affected | ||
com.vaadin:flow-serverBrowse Maven / com.vaadin:flow-server | GitHub Advisory | 1.0.0 to < 1.0.21 · Fixed in 1.0.21 | affected |
| 1.1.0 to < 2.9.3 · Fixed in 2.9.3 | affected | ||
| 3.0.0 to < 9.1.2 · Fixed in 9.1.2 | affected | ||
| 23.0.0 to < 23.3.13 · Fixed in 23.3.13 | affected | ||
| 24.0.0 to < 24.0.9 · Fixed in 24.0.9 | affected | ||
| 24.1.alpha1 to < 24.1.0 · Fixed in 24.1.0 | affected | ||
com.vaadin:vaadinBrowse Maven / com.vaadin:vaadin | GitHub Advisory | 24.0.0 to < 24.0.7 · Fixed in 24.0.7 | affected |
| 24.1.0.alpha1 to < 24.1.0 · Fixed in 24.1.0 | affected | ||
| 10.0.0 to < 10.0.24 · Fixed in 10.0.24 | affected | ||
| 11.0.0 to < 14.10.2 · Fixed in 14.10.2 | affected | ||
| 15.0.0 to < 22.1.0 · Fixed in 22.1.0 | affected | ||
| 23.0.0 to < 23.3.14 · Fixed in 23.3.14 | affected |
References
5github.com
https://github.com/vaadin/platform github.com
https://github.com/vaadin/platform/security/advisories/GHSA-ch48-9r3q-pv7x nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-25500 vaadin.com
https://vaadin.com/security/cve-2023-25500