{"id":"CVE-2020-36321","details":"Improper URL validation in development mode handler in com.vaadin:flow-server versions 2.0.0 through 2.4.1 (Vaadin 14.0.0 through 14.4.2), and 3.0 prior to 5.0 (Vaadin 15 prior to 18) allows attacker to request arbitrary files stored outside of intended frontend resources folder.","aliases":["GHSA-49r2-73m6-pp8f"],"modified":"2026-08-07T15:12:39.375686Z","published":"2021-04-23T16:15:08.403Z","references":[{"type":"ADVISORY","url":"https://vaadin.com/security/cve-2020-36321"},{"type":"FIX","url":"https://github.com/vaadin/flow/pull/9392"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/vaadin/flow","events":[{"introduced":"8e306579f157678c3baa3f3f63f406d073668161"},{"fixed":"4623398d1c6817fb6e7e7ae8d05f54cede9c45ee"},{"introduced":"4b6ca4330163c4e976b32d03880fe2154a9d1ca7"},{"fixed":"60b4fd8e59948e2a6a5f8af1988a3adc45563ffc"}],"database_specific":{"cpe":"cpe:2.3:a:vaadin:flow:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"2.0.0"},{"fixed":"2.4.2"},{"introduced":"3.0.0"},{"fixed":"5.0.0"}],"source":"CPE_RANGE"}}],"versions":["5.0.0.rc1","5.0.0.beta1","2.4.1","2.4.0","5.0.0.alpha1","2.4.0.beta2","2.4.0.beta1","2.4.0.alpha1","2.3.4","2.3.3","4.0.0.beta1","2.3.2","4.0.0.alpha3","2.3.1","4.0.0.alpha2","2.3.0","4.0.0.alpha1","2.3.0.beta3","2.3.0.beta2","3.2.0.alpha7","2.3.0.beta1","3.2.0.alpha6","3.2.0.alpha5","3.2.0.alpha4","2.3.0.alpha1","2.2.0.rc1","3.2.0.alpha3","2.2.0.beta2","3.2.0.alpha2","2.2.0.beta1","3.2.0.alpha1","2.2.0.alpha16","2.2.0.alpha15","2.2.0.alpha14","3.0.0.beta2","2.2.alpha14","3.0.0.beta4","3.0.0.beta3","2.2.0.alpha13","3.0.0.beta1","3.0.0.alpha17","2.2.0.alpha12","2.2.0.alpha11","2.2.0.alpha10","2.2.0.alpha9","2.2.0.alpha8","2.2.0.alpha7","2.2.0.alpha6","2.2.0.alpha5","2.2.0.alpha4","2.2.0.alpha3","2.2.0.alpha2","2.2.0.alpha1","2.1.0.beta3","3.0.0.alpha5","2.1.0.beta1","2.1.0.alpha1","2.0.8","2.0.7","2.0.6","2.0.5","2.0.4","2.0.3","2.0.2","2.0.1","2.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-36321.json","vanir_signatures_modified":"2026-08-07T15:12:39Z","vanir_signatures":[{"target":{"function":"assertMultipartResponse","file":"flow-server/src/test/java/com/vaadin/flow/internal/ResponseWriterTest.java"},"deprecated":false,"digest":{"function_hash":"249622570144799160707345132873329528777","length":1300},"id":"CVE-2020-36321-0d26ca84","signature_type":"Function","signature_version":"v1","source":"https://github.com/vaadin/flow/commit/60b4fd8e59948e2a6a5f8af1988a3adc45563ffc"},{"target":{"file":"flow-server/src/test/java/com/vaadin/flow/internal/ResponseWriterTest.java"},"deprecated":false,"digest":{"line_hashes":["153177363219435303937481346278910453140","181422030205452905305290291040049227309","33971829593394412345599048598093718036","275041624494612527645552893294291103394","86469247458738357383103507442104737069","25922342559461617944053885903640254293","232339524840583842812333248918319678667"],"threshold":0.9},"id":"CVE-2020-36321-417a7d8e","signature_type":"Line","signature_version":"v1","source":"https://github.com/vaadin/flow/commit/60b4fd8e59948e2a6a5f8af1988a3adc45563ffc"},{"id":"CVE-2020-36321-a61406d4","signature_type":"Line","signature_version":"v1","source":"https://github.com/vaadin/flow/commit/60b4fd8e59948e2a6a5f8af1988a3adc45563ffc","target":{"file":"flow-server/src/main/java/com/vaadin/flow/internal/ResponseWriter.java"},"deprecated":false,"digest":{"line_hashes":["43520808278726046006432504985646778166","296123810924565338498643766530874911587","221259991966709583237594580063444196171","108437677596457758235630426291300831986","317700053554754753249584371690674619316","161853292399189728664655237763082637062","27953669406768766753844549422154923759","271721621782024497285018147912205502689","97433726130074578806977607204725840712","153742533932158225961900960708720470033","275096766594378320841425464416028224121","106015272132669031337108147864651992326","172585572563459339251084935163900343552","118576641918442202000303694882491631629","159566678862912923854403932800634387798","250832752003912735365863795960963851311","95251104644391592641027354560185502492","285848104943858832560397642457555650382","315036448805680584430042212921432466215","255473002469754674093051837237214340125","230235063635031316715263929865930818925","322837197650918553560479406135892037458","74990952378373315520732252202114369521","315036448805680584430042212921432466215","80656763328939012405066971435088009862","184993245847957223953294561761420966511","27613114131117876128238304830026711186","310898117397158724705314868744425276684","211579530431730291031803728089338761891","155912885843459940685605779617059510580","99375202491282114146738158083936559773"],"threshold":0.9}},{"id":"CVE-2020-36321-e6f3accf","signature_type":"Function","signature_version":"v1","source":"https://github.com/vaadin/flow/commit/60b4fd8e59948e2a6a5f8af1988a3adc45563ffc","target":{"file":"flow-server/src/main/java/com/vaadin/flow/internal/ResponseWriter.java","function":"writeRangeContents"},"deprecated":false,"digest":{"function_hash":"299806186407132363208599384657169049253","length":1587}}]}},{"ranges":[{"type":"GIT","repo":"https://github.com/vaadin/platform","events":[{"introduced":"1497812ad40b7ff90bef8bdb28808afc8d7194d1"},{"fixed":"f052a3723576ff39af54d475c25a328e0547b34b"},{"introduced":"354ad0186b5e61b548adad84de03af297dc6f2a6"},{"fixed":"0f6048aefc10582e3042adb05064dac232f2f2c9"}],"database_specific":{"cpe":"cpe:2.3:a:vaadin:vaadin:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"14.0.0"},{"fixed":"14.4.3"},{"introduced":"15.0.0"},{"fixed":"18.0.0"}],"source":"CPE_RANGE"}}],"versions":["18.0.0.rc2","18.0.0.rc1","18.0.0.beta3","18.0.0.beta2","18.0.0.beta1","14.4.2","14.4.1","18.0.0.alpha1","14.4.0","14.4.0.rc1","14.4.0.beta2","14.4.0.beta1","14.4.0.alpha1","17.0.0","17.0.0.rc2","17.0.0.rc1","17.0.0.beta3","17.0.0.beta2","17.0.0.beta1","17.0.0.alpha7","17.0.0.alpha6","16.0.1","14.3.0.rc1","14.3.0","14.3.0.beta3","17.0.0.alpha5","14.3.0.beta2","14.3.0.beta1","17.0.0.alpha4","17.0.0.alpha3","17.0.0.alpha2","14.3.0.alpha1","14.2.0","14.2.0.rc1","14.2.0.beta1","16.0.0.alpha3","16.0.0.alpha2","14.2.0.alpha11","16.0.0.alpha1","14.2.0.alpha10","14.2.0.alpha9","14.2.0.alpha8","14.2.0.alpha7","14.2.0.alpha6","15.0.0.rc1","15.0.0","14.2.0.alpha5","14.2.0.alpha4","14.2.0.alpha3","14.2.0.alpha2","14.2.0.alpha1","14.1.2","14.1.1","14.1.0","14.1.0.beta2","14.1.0.beta1","14.1.0.alpha3","14.1.0.alpha1","14.0.2","14.0.1","14.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-36321.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/vaadin/vaadin","events":[{"introduced":"ca9cf99092245a31a84b317adf1d79a397970d27"},{"fixed":"e9b8eba22d382c574a5a7a11a68afd09e7eaa39d"},{"introduced":"9efda1b1e0a27769eef9292dd7799d8fea77e633"},{"fixed":"a5bc6b4832e649fb16243e2bc0ee9b2941815e3b"}],"database_specific":{"extracted_events":[{"introduced":"14.0.0"},{"fixed":"14.4.3"},{"introduced":"15.0.0"},{"fixed":"18.0.0"}],"source":"CPE_RANGE","cpe":"cpe:2.3:a:vaadin:vaadin:*:*:*:*:*:*:*:*"}}],"versions":["v14.4.0","v18.0.0-beta2","v18.0.0-rc2","v18.0.0-rc1","v18.0.0-beta3","v14.4.2","v18.0.0-beta1","v18.0.0-alpha1","v14.4.1","v17.0.0","v14.4.0-rc1","v14.4.0-beta2","v14.4.0-beta1","v14.4.0-alpha1","v17.0.0-rc1","v14.3.0","v17.0.0-rc2","v17.0.0-beta3","v17.0.0-beta2","v17.0.0-beta1","v17.0.0-alpha7","v17.0.0-alpha6","v17.0.0-alpha5","v14.3.0-rc1","v14.3.0-beta3","v17.0.0-alpha4","v14.3.0-beta2","v14.3.0-beta1","v14.3.0-alpha1","v17.0.0-alpha3","v14.2.0","v17.0.0-alpha2","v17.0.0-alpha1","v16.0.0-alpha3","v14.2.0-rc1","v14.2.0-beta1","v14.2.0-alpha11","v16.0.0-alpha2","v16.0.0-alpha1","v14.2.0-alpha10","v15.0.0-rc1","v14.2.0-alpha9","v14.2.0-alpha8","v14.2.0-alpha7","v14.2.0-alpha6","v14.2.0-alpha5","v15.0.0-beta5","v14.2.0-alpha4","v15.0.0-beta4","v15.0.0-beta3","v15.0.0-beta2","v15.0.0-beta1","v14.2.0-alpha3","v15.0.0-alpha15","v15.0.0-alpha14","v15.0.0-alpha13","v15.0.0-alpha12","v15.0.0-alpha11","v14.2.0-alpha2","v15.0.0-alpha10","v14.2.0-alpha1","v14.1.2","v15.0.0-alpha9","v15.0.0-alpha8","v15.0.0-alpha7","v14.1.1","v15.0.0-alpha6","v15.0.0-alpha5","v14.1.0","v14.1.0-rc1","v15.0.0-alpha4","v14.1.0-beta3","v14.1.0-beta2","v14.1.0-beta1","v15.0.0-alpha3","v14.1.0-alpha5","v15.0.0-alpha2","v14.1.0-alpha4","v14.1.0-alpha3","v14.1.0-alpha2","v15.0.0-alpha1","v14.1.0-alpha1","v14.0.2","v14.0.1","v14.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-36321.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}