ZeroHour

CVE-2018-25007

CVSS 3.1
4.3 medium
EPSS
<1%p45
Published
()
Modified
Description

Missing check in UIDL request handler in com.vaadin:flow-server versions 1.0.0 through 1.0.5 (Vaadin 10.0.0 through 10.0.7, and 11.0.0 through 11.0.2) allows attacker to update element property values via crafted synchronization message.

Vendors
vaadin
Products
flow, vaadin
Weakness
CWE-754
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.