github.com
https://github.com/vaadin/platform GHSA-76F4-FW33-6J2V
Potential sensitive data exposure in applications using Vaadin 15
Description
Insecure configuration of default `ObjectMapper` in `com.vaadin:flow-server` versions 3.0.0 through 3.0.5 (Vaadin 15.0.0 through 15.0.4) may expose sensitive data if the application also uses e.g. `@RestController` - https://vaadin.com/security/cve-2020-36319
Description source: GitHub Advisory
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
com.vaadin:vaadin-bomBrowse Maven / com.vaadin:vaadin-bom | GitHub Advisory | 15.0.0 to < 15.0.5 · Fixed in 15.0.5 | affected |
References
3github.com
https://github.com/vaadin/platform/security/advisories/GHSA-76f4-fw33-6j2v vaadin.com
https://vaadin.com/security/cve-2020-36319