{"id":"GHSA-93c4-vf86-3rj7","summary":"Reflected cross-site scripting in vaadin-menu-bar webjar resources in Vaadin 14","details":"Missing output sanitization in test sources in `org.webjars.bowergithub.vaadin:vaadin-menu-bar` versions 1.0.0 through 1.2.0 (Vaadin 14.0.0 through 14.4.4) allows remote attackers to execute malicious JavaScript in browser by opening crafted URL.","aliases":["CVE-2021-33611"],"modified":"2023-11-08T04:06:05.923539Z","published":"2021-11-03T17:33:32Z","database_specific":{"nvd_published_at":"2021-11-02T10:15:00Z","cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2021-11-02T19:53:07Z"},"references":[{"type":"WEB","url":"https://github.com/vaadin/platform/security/advisories/GHSA-93c4-vf86-3rj7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-33611"},{"type":"WEB","url":"https://github.com/vaadin/vaadin-menu-bar/pull/126"},{"type":"PACKAGE","url":"https://github.com/vaadin/platform"},{"type":"WEB","url":"https://vaadin.com/security/cve-2021-33611"}],"affected":[{"package":{"name":"com.vaadin:vaadin-bom","ecosystem":"Maven","purl":"pkg:maven/com.vaadin/vaadin-bom"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"14.0.0"},{"fixed":"14.4.5"}]}],"versions":["14.0.0","14.0.1","14.0.10","14.0.11","14.0.12","14.0.13","14.0.14","14.0.15","14.0.2","14.0.3","14.0.4","14.0.5","14.0.6","14.0.7","14.0.8","14.0.9","14.1.0","14.1.1","14.1.16","14.1.17","14.1.18","14.1.19","14.1.2","14.1.20","14.1.21","14.1.22","14.1.23","14.1.24","14.1.25","14.1.26","14.1.27","14.1.28","14.1.3","14.1.4","14.1.5","14.2.0","14.2.1","14.2.2","14.2.3","14.3.0","14.3.1","14.3.2","14.3.3","14.3.4","14.3.5","14.3.6","14.3.7","14.3.8","14.3.9","14.4.0","14.4.1","14.4.2","14.4.3","14.4.4"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/11/GHSA-93c4-vf86-3rj7/GHSA-93c4-vf86-3rj7.json","last_known_affected_version_range":"\u003c= 14.4.4"}},{"package":{"name":"org.webjars.bowergithub.vaadin:vaadin-menu-bar","ecosystem":"Maven","purl":"pkg:maven/org.webjars.bowergithub.vaadin/vaadin-menu-bar"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.0.0"},{"fixed":"1.2.1"}]}],"versions":["1.0.0","1.0.1","1.0.2","1.0.3","1.0.4","1.0.5","1.1.0","1.1.0-alpha1","1.1.0-alpha2","1.2.0","1.2.0-alpha1","1.2.0-beta1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/11/GHSA-93c4-vf86-3rj7/GHSA-93c4-vf86-3rj7.json","last_known_affected_version_range":"\u003c= 1.2.0"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}