Server classes and resources exposure in OSGi applications using Vaadin 12-14 and 19
Package
Affected versions
>= 12.0.0, < 14.4.10
= 19.0.0
Patched versions
14.4.10
19.0.1
Description
Reviewed
Apr 16, 2021
Published to the GitHub Advisory Database
Apr 19, 2021
Last updated
Jan 9, 2023
Vulnerability in OSGi integration in
com.vaadin:flow-server
versions 1.2.0 through 2.4.7 (Vaadin 12.0.0 through 14.4.9), and 6.0.0 through 6.0.1 (Vaadin 19.0.0) allows attacker to access application classes and resources on the server via crafted HTTP request.References