{"id":"GHSA-76f4-fw33-6j2v","summary":"Potential sensitive data exposure in applications using Vaadin 15","details":"Insecure configuration of default `ObjectMapper` in `com.vaadin:flow-server` versions 3.0.0 through 3.0.5 (Vaadin 15.0.0 through 15.0.4) may expose sensitive data if the application also uses e.g. `@RestController`\n\n- https://vaadin.com/security/cve-2020-36319","modified":"2024-12-02T05:26:03.528Z","published":"2021-04-19T14:48:26Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2021-04-16T23:14:31Z","nvd_published_at":null,"cwe_ids":["CWE-200"],"severity":"LOW"},"references":[{"type":"WEB","url":"https://github.com/vaadin/platform/security/advisories/GHSA-76f4-fw33-6j2v"},{"type":"PACKAGE","url":"https://github.com/vaadin/platform"},{"type":"WEB","url":"https://vaadin.com/security/cve-2020-36319"}],"affected":[{"package":{"name":"com.vaadin:vaadin-bom","ecosystem":"Maven","purl":"pkg:maven/com.vaadin/vaadin-bom"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"15.0.0"},{"fixed":"15.0.5"}]}],"versions":["15.0.0","15.0.1","15.0.2","15.0.3","15.0.4"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/04/GHSA-76f4-fw33-6j2v/GHSA-76f4-fw33-6j2v.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"}]}