{"id":"GHSA-3h5r-928v-mxhh","summary":"Unauthorized client-side property update in UIDL request handler in Vaadin 10 and 11","details":"Missing check in UIDL request handler in `com.vaadin:flow-server` versions 1.0.0 through 1.0.5 (Vaadin 10.0.0 through 10.0.7, and 11.0.0 through 11.0.2) allows attacker to update element property values via crafted synchronization message.\n\n- https://vaadin.com/security/cve-2018-25007","modified":"2024-12-02T05:55:11.439626Z","published":"2021-04-19T14:49:13Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-754"],"severity":"LOW","github_reviewed":true,"github_reviewed_at":"2021-04-16T23:14:45Z"},"references":[{"type":"WEB","url":"https://github.com/vaadin/platform/security/advisories/GHSA-3h5r-928v-mxhh"},{"type":"PACKAGE","url":"https://github.com/vaadin/platform"},{"type":"WEB","url":"https://vaadin.com/security/cve-2018-25007"}],"affected":[{"package":{"name":"com.vaadin:vaadin-bom","ecosystem":"Maven","purl":"pkg:maven/com.vaadin/vaadin-bom"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"10.0.0"},{"fixed":"10.0.8"}]}],"versions":["10.0.0","10.0.1","10.0.2","10.0.3","10.0.4","10.0.5","10.0.6","10.0.7"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/04/GHSA-3h5r-928v-mxhh/GHSA-3h5r-928v-mxhh.json"}},{"package":{"name":"com.vaadin:vaadin-bom","ecosystem":"Maven","purl":"pkg:maven/com.vaadin/vaadin-bom"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"11.0.0"},{"fixed":"11.0.3"}]}],"versions":["11.0.0","11.0.1","11.0.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/04/GHSA-3h5r-928v-mxhh/GHSA-3h5r-928v-mxhh.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N"}]}