{"id":"CVE-2021-31411","details":"Insecure temporary directory usage in frontend build functionality of com.vaadin:flow-server versions 2.0.9 through 2.5.2 (Vaadin 14.0.3 through Vaadin 14.5.2), 3.0 prior to 6.0 (Vaadin 15 prior to 19), and 6.0.0 through 6.0.5 (Vaadin 19.0.0 through 19.0.4) allows local users to inject malicious code into frontend resources during application rebuilds.","aliases":["GHSA-p826-8vhq-h439"],"modified":"2026-08-07T16:50:19.944846Z","published":"2021-05-05T19:15:08.777Z","references":[{"type":"ADVISORY","url":"https://vaadin.com/security/cve-2021-31411"},{"type":"FIX","url":"https://github.com/vaadin/flow/pull/10640"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/vaadin/flow","events":[{"introduced":"058a0e568a95bc163a7bb35a56c0ea4b56fe9e21"},{"fixed":"995027d29ee538e7f707b2454686be75f02977ef"},{"introduced":"4b6ca4330163c4e976b32d03880fe2154a9d1ca7"},{"last_affected":"60b4fd8e59948e2a6a5f8af1988a3adc45563ffc"},{"introduced":"6a409a8b4b01b18dc2ca30c59395aeeb0cffbd2c"},{"last_affected":"e2e141cc0be9fbea64ba29ea4824232639c36dbb"}],"database_specific":{"cpe":"cpe:2.3:a:vaadin:flow:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"2.0.9"},{"fixed":"2.5.3"},{"introduced":"3.0.0"},{"last_affected":"5.0.0"},{"introduced":"6.0.0"},{"last_affected":"6.0.6"}],"source":"CPE_RANGE"}}],"versions":["6.0.6","6.0.5","6.0.4","6.0.3","6.0.2","6.0.1","6.0.0.rc1","6.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-31411.json","vanir_signatures_modified":"2026-08-07T16:50:19Z","vanir_signatures":[{"signature_version":"v1","source":"https://github.com/vaadin/flow/commit/995027d29ee538e7f707b2454686be75f02977ef","target":{"file":"flow-server/src/main/java/com/vaadin/flow/server/frontend/JarContentsManager.java"},"deprecated":false,"digest":{"line_hashes":["274118860405830707737187343030887766150","327559721548196134147450388879998528952","231391270674709341178973814261592708464","211979396369304634247134746982955007251","32900508480395475606250217170485575868","80791419901938608036810617882838820733","6026733202762934250207559657693826010","17187701696772157707955369838765636321","14585976683169020273786467247984779635","136419670407895535633809878805326991124","60136359027831226858976120404744046768","171023654744543184735012727835208935228","48270102157939833231118982497687312218","175188813783905405808930999300082626303","220604571186367106147995826939082644094","15956785489358244696973139203321284713","133908307871722389377786052986188030614","172201478849480036233153468210094773069","16731467310513679515719110523690099220","325339830852643423504391538910603562036","220115242206324016293745746735881530016","139147795175099503122261681307185114248","126281408131594152747505327874700784215"],"threshold":0.9},"id":"CVE-2021-31411-5f3d7805","signature_type":"Line"},{"digest":{"function_hash":"241441924087109472839976369467669757191","length":802},"id":"CVE-2021-31411-e6b195bb","signature_type":"Function","signature_version":"v1","source":"https://github.com/vaadin/flow/commit/995027d29ee538e7f707b2454686be75f02977ef","target":{"file":"flow-server/src/main/java/com/vaadin/flow/server/frontend/JarContentsManager.java","function":"copyJarEntryTrimmingBasePath"},"deprecated":false}]}},{"ranges":[{"type":"GIT","repo":"https://github.com/vaadin/platform","events":[{"introduced":"23851fec3ccb0b849c34e84ea571f6306263f672"},{"fixed":"e92afa6958bc1fb6d0d82f19eef9290264a29e0b"},{"introduced":"354ad0186b5e61b548adad84de03af297dc6f2a6"},{"fixed":"5c2f4eb79bc12e314d269b0a96c25e5a68e1c51d"}],"database_specific":{"cpe":"cpe:2.3:a:vaadin:vaadin:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"14.0.3"},{"fixed":"14.5.3"},{"introduced":"15.0.0"},{"fixed":"19.0.5"}],"source":"CPE_RANGE"}}],"versions":["19.0.4","19.0.3","19.0.2","19.0.1","19.0.0","19.0.0.rc1","19.0.0.beta3","19.0.0.beta2","19.0.0.beta1","19.0.0.alpha5","19.0.0.alpha4","19.0.0.alpha3","19.0.0.alpha2","19.0.0.alpha1","18.0.0.beta2","18.0.0.beta1","18.0.0.alpha1","17.0.0","17.0.0.rc2","17.0.0.rc1","17.0.0.beta3","17.0.0.beta2","17.0.0.beta1","17.0.0.alpha7","17.0.0.alpha6","16.0.1","17.0.0.alpha5","17.0.0.alpha4","17.0.0.alpha3","17.0.0.alpha2","16.0.0.alpha3","16.0.0.alpha2","16.0.0.alpha1","15.0.0.rc1","15.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-31411.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/vaadin/vaadin","events":[{"introduced":"133ed383767f8c3993cd6142c7232b089f9c5df5"},{"fixed":"9c79fd20b941639197ea58d6633722909b2ea3c7"},{"introduced":"9efda1b1e0a27769eef9292dd7799d8fea77e633"},{"fixed":"d54fe8ecafbc2254fe0d23134787bdaf2210d9ac"}],"database_specific":{"source":"CPE_RANGE","cpe":"cpe:2.3:a:vaadin:vaadin:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"14.0.3"},{"fixed":"14.5.3"},{"introduced":"15.0.0"},{"fixed":"19.0.5"}]}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-31411.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}