{"id":"CVE-2021-33611","details":"Missing output sanitization in test sources in org.webjars.bowergithub.vaadin:vaadin-menu-bar versions 1.0.0 through 1.2.0 (Vaadin 14.0.0 through 14.4.4) allows remote attackers to execute malicious JavaScript in browser by opening crafted URL","aliases":["GHSA-93c4-vf86-3rj7"],"modified":"2026-07-08T22:14:03.570199Z","published":"2021-11-02T10:15:07.683Z","references":[{"type":"FIX","url":"https://github.com/vaadin/vaadin-menu-bar/pull/126"},{"type":"EVIDENCE","url":"https://vaadin.com/security/cve-2021-33611"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/vaadin/vaadin","events":[{"introduced":"ca9cf99092245a31a84b317adf1d79a397970d27"},{"fixed":"3411feab4bba930a1b2f0e2067d749708e652359"}],"database_specific":{"extracted_events":[{"introduced":"14.0.0"},{"fixed":"14.4.4"}],"source":"DESCRIPTION"}}],"versions":["v14.4.0","v14.4.3","v14.4.2","v14.4.1","v14.4.0-rc1","v14.4.0-beta2","v14.4.0-beta1","v14.4.0-alpha1","v14.3.0","v14.3.0-rc1","v14.3.0-beta3","v14.3.0-beta2","v14.3.0-beta1","v14.3.0-alpha1","v14.2.0","v14.2.0-rc1","v14.2.0-beta1","v14.2.0-alpha11","v14.2.0-alpha10","v14.2.0-alpha9","v14.2.0-alpha8","v14.2.0-alpha7","v14.2.0-alpha6","v14.2.0-alpha5","v14.2.0-alpha4","v14.2.0-alpha3","v14.2.0-alpha2","v14.2.0-alpha1","v14.1.2","v14.1.1","v14.1.0","v14.1.0-rc1","v14.1.0-beta3","v14.1.0-beta2","v14.1.0-beta1","v14.1.0-alpha5","v14.1.0-alpha4","v14.1.0-alpha3","v14.1.0-alpha2","v14.1.0-alpha1","v14.0.2","v14.0.1","v14.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-33611.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/vaadin/vaadin-menu-bar","events":[{"introduced":"07891345ef8f413ae49317d1241ac3e4b095a3d6"},{"fixed":"efb92bb0fdd7b78182b133c134c4e38063220e70"}],"database_specific":{"extracted_events":[{"introduced":"1.0.0"},{"fixed":"1.2.0"}],"source":"DESCRIPTION"}}],"versions":["v1.2.0-beta1","v1.2.0-alpha1","v1.1.0","v1.1.0-alpha2","v1.1.0-alpha1","v1.0.5","v1.0.4","v1.0.3","v1.0.2","v1.0.1","v1.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-33611.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}