Record summary

CVE-2023-25500 has a selected CVSS score of 3.5 (low).

Description

Possible information disclosure in Vaadin 10.0.0 to 10.0.23, 11.0.0 to 14.10.1, 15.0.0 to 22.0.28, 23.0.0 to 23.3.13, 24.0.0 to 24.0.6, 24.1.0.alpha1 to 24.1.0.rc2, resulting in potential information disclosure of class and method names in RPC responses by sending modified requests.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 5, 2024 · Source: CVE List

Affected products and versions

4
ProductSourceVersion rangeStatus

Default status: unaffected

CVE List1.0.0 to ≤ 1.0.20affected
1.1.0 to ≤ 2.9.2affected
3.0.0 to ≤ 9.1.1affected
23.0.0 to ≤ 23.3.12affected
24.0.0 to ≤ 24.0.8affected
24.1.0.alpha1 to ≤ 24.1.0.rc3affected

Default status: unaffected

CVE List10.0.0 to ≤ 10.0.23affected
11.0.0 to ≤ 14.10.1affected
15.0.0 to ≤ 22.0.8affected
23.0.0 to ≤ 23.3.13affected
24.0.0 to ≤ 24.0.6affected
24.1.0.alpha1 to ≤ 24.1.0.rc2affected
GitHub Advisory1.0.0 to < 1.0.21 · Fixed in 1.0.21affected
1.1.0 to < 2.9.3 · Fixed in 2.9.3affected
3.0.0 to < 9.1.2 · Fixed in 9.1.2affected
23.0.0 to < 23.3.13 · Fixed in 23.3.13affected
24.0.0 to < 24.0.9 · Fixed in 24.0.9affected
24.1.alpha1 to < 24.1.0 · Fixed in 24.1.0affected
GitHub Advisory24.0.0 to < 24.0.7 · Fixed in 24.0.7affected
24.1.0.alpha1 to < 24.1.0 · Fixed in 24.1.0affected
10.0.0 to < 10.0.24 · Fixed in 10.0.24affected
11.0.0 to < 14.10.2 · Fixed in 14.10.2affected
15.0.0 to < 22.1.0 · Fixed in 22.1.0affected
23.0.0 to < 23.3.14 · Fixed in 23.3.14affected

References

5