{"id":"CVE-2021-31407","details":"Vulnerability in OSGi integration in com.vaadin:flow-server versions 1.2.0 through 2.4.7 (Vaadin 12.0.0 through 14.4.9), and 6.0.0 through 6.0.1 (Vaadin 19.0.0) allows attacker to access application classes and resources on the server via crafted HTTP request.","aliases":["GHSA-25xc-jwfq-39jw"],"modified":"2026-08-07T16:50:22.749079Z","published":"2021-04-23T16:15:08.767Z","references":[{"type":"ADVISORY","url":"https://vaadin.com/security/cve-2021-31407"},{"type":"FIX","url":"https://github.com/vaadin/flow/pull/10229"},{"type":"FIX","url":"https://github.com/vaadin/flow/pull/10269"},{"type":"FIX","url":"https://github.com/vaadin/osgi/issues/50"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/vaadin/flow","events":[{"introduced":"9aee02bb461b537242243218e25dcbe200aa2cbe"},{"fixed":"ada7f7be8fa6c938941674de8650ce6921aec60d"},{"introduced":"6a409a8b4b01b18dc2ca30c59395aeeb0cffbd2c"},{"fixed":"eeffcf5ff22632c02aaa912cf024a29cbbaad311"}],"database_specific":{"cpe":"cpe:2.3:a:vaadin:flow:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"1.2.0"},{"fixed":"2.4.8"},{"introduced":"6.0.0"},{"fixed":"6.0.2"}],"source":"CPE_RANGE"}}],"versions":["2.4.7","6.0.1","6.0.0.rc1","6.0.0","2.4.6","2.4.5","2.4.4","2.4.3","2.4.2","2.4.1","2.4.0","2.4.0.beta2","2.4.0.beta1","2.4.0.alpha1","2.3.4","2.3.3","2.3.2","2.3.1","2.3.0","2.3.0.beta3","2.3.0.beta2","2.3.0.beta1","2.3.0.alpha1","2.2.0.rc1","2.2.0.beta2","2.2.0.beta1","2.2.0.alpha16","2.2.0.alpha15","2.2.0.alpha14","2.2.alpha14","2.2.0.alpha13","2.2.0.alpha12","2.2.0.alpha11","2.2.0.alpha10","2.2.0.alpha9","2.2.0.alpha8","2.2.0.alpha7","2.2.0.alpha6","2.2.0.alpha5","2.2.0.alpha4","2.2.0.alpha3","2.2.0.alpha2","2.2.0.alpha1","2.1.0.beta3","3.0.0.alpha5","2.1.0.beta1","2.1.0.alpha1","2.0.8","2.0.7","2.0.6","2.0.5","2.0.4","2.0.3","2.0.2","2.0.1","2.0.0","2.0.0.rc3","2.0.0.rc2","2.0.0.rc1","2.0.0.beta2","2.0.0.beta1","2.0.0.alpha5","1.5.0.alpha4","1.5.0.alpha3","1.5.0.alpha2","1.5.0.alpha1","1.3.0.alpha3","1.3.0.alpha2","1.2.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-31407.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/vaadin/platform","events":[{"introduced":"07d2173b5a200b7c8e7d12831b3681b22ff76aae"},{"fixed":"81ed2884a0f9c43bf21a72d1da801052e567b78b"},{"introduced":"5c28d4e1b9099122cf4d770283777f00a960aab3"},{"last_affected":"5c28d4e1b9099122cf4d770283777f00a960aab3"}],"database_specific":{"cpe":["cpe:2.3:a:vaadin:vaadin:*:*:*:*:*:*:*:*","cpe:2.3:a:vaadin:vaadin:19.0.0:-:*:*:*:*:*:*"],"extracted_events":[{"introduced":"12.0.0"},{"fixed":"14.4.10"},{"introduced":"19.0.0-NA"},{"last_affected":"19.0.0-NA"}],"source":["CPE_RANGE","CPE_STRING"]}}],"versions":["19.0.0-NA","19.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-31407.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/vaadin/vaadin","events":[{"introduced":"6cdfffb48905fb0690b4b3d545cd65539a073323"},{"fixed":"6f36424c2e3544ea5fffdad8a6db927f8c109338"},{"introduced":"3981409421683b6f4a796f37b67433d36b6a7ca1"},{"last_affected":"3981409421683b6f4a796f37b67433d36b6a7ca1"}],"database_specific":{"source":["CPE_RANGE","CPE_STRING"],"cpe":["cpe:2.3:a:vaadin:vaadin:*:*:*:*:*:*:*:*","cpe:2.3:a:vaadin:vaadin:19.0.0:-:*:*:*:*:*:*"],"extracted_events":[{"introduced":"12.0.0"},{"fixed":"14.4.10"},{"introduced":"19.0.0-NA"},{"last_affected":"19.0.0-NA"}]}}],"versions":["19.0.0-NA","v14.4.9","v19.0.0","v14.4.8","v14.4.7","v14.4.0","v14.4.6","v14.4.5","v14.4.4","v14.4.3","v14.4.2","v14.4.1","v14.4.0-rc1","v14.4.0-beta2","v14.4.0-beta1","v14.4.0-alpha1","v14.3.0","v14.3.0-rc1","v14.3.0-beta3","v14.3.0-beta2","v14.3.0-beta1","v14.3.0-alpha1","v14.2.0","v14.2.0-rc1","v14.2.0-beta1","v14.2.0-alpha11","v14.2.0-alpha10","v14.2.0-alpha9","v14.2.0-alpha8","v14.2.0-alpha7","v14.2.0-alpha6","v14.2.0-alpha5","v14.2.0-alpha4","v14.2.0-alpha3","v14.2.0-alpha2","v14.2.0-alpha1","v14.1.2","v14.1.1","v14.1.0","v14.1.0-rc1","v14.1.0-beta3","v14.1.0-beta2","v14.1.0-beta1","v14.1.0-alpha5","v14.1.0-alpha4","v14.1.0-alpha3","v14.1.0-alpha2","v14.1.0-alpha1","v14.0.2","v14.0.1","v14.0.0","v14.0.0-rc9","v14.0.0-rc8","v14.0.0-rc7","v14.0.0-rc6","v14.0.0-rc5","v14.0.0-rc4","v14.0.0-rc3","v14.0.0-rc2","v14.0.0-rc1","v14.0.0-beta3","v14.0.0-beta2","v14.0.0-beta1","v14.0.0-alpha4","v14.0.0-alpha3","v14.0.0-alpha2","v14.0.0-alpha1","v13.0.1","v13.0.0","v13.0.0-beta3","v13.0.0-beta2","v13.0.0-beta1","v13.0.0-alpha4","v13.0.0-alpha3","v13.0.0-alpha2","v13.0.0-alpha1","v12.0.2","v12.0.1","v12.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-31407.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}