github.com
https://github.com/vaadin/platform GHSA-JQJ4-R483-4GVR
Reflected cross-site scripting in default RouteNotFoundError view in Vaadin 10 and 11-13
Description
Missing output sanitization in default `RouteNotFoundError` view in `com.vaadin:flow-server` versions 1.0.0 through 1.0.10 (Vaadin 10.0.0 through 10.0.13), and 1.1.0 through 1.4.2 (Vaadin 11.0.0 through 13.0.5) allows attacker to execute malicious JavaScript via crafted URL. - https://vaadin.com/security/cve-2019-25027
Description source: GitHub Advisory
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
com.vaadin:vaadin-bomBrowse Maven / com.vaadin:vaadin-bom | GitHub Advisory | 10.0.0 to < 10.0.14 · Fixed in 10.0.14 | affected |
| 11.0.0 to < 13.0.6 · Fixed in 13.0.6 | affected |
References
3github.com
https://github.com/vaadin/platform/security/advisories/GHSA-jqj4-r483-4gvr vaadin.com
https://vaadin.com/security/cve-2019-25027