{"id":"GHSA-9h6g-6mxg-vvp4","summary":"Timing side channel vulnerability in endpoint request handler in Vaadin 15-19","details":"Non-constant-time comparison of CSRF tokens in endpoint request handler in `com.vaadin:flow-server` versions 3.0.0 through 5.0.3 (Vaadin 15.0.0 through 18.0.6), and com.vaadin:fusion-endpoint version 6.0.0 (Vaadin 19.0.0) allows attacker to guess a security token for Fusion endpoints via timing attack.\n\n- https://vaadin.com/security/cve-2021-31406","modified":"2024-12-02T05:45:00.685897Z","published":"2021-04-19T14:47:18Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2021-04-16T23:13:06Z","nvd_published_at":null,"cwe_ids":["CWE-208"],"severity":"MODERATE"},"references":[{"type":"WEB","url":"https://github.com/vaadin/platform/security/advisories/GHSA-9h6g-6mxg-vvp4"},{"type":"WEB","url":"https://github.com/vaadin/platform"},{"type":"WEB","url":"https://vaadin.com/security/cve-2021-31406"}],"affected":[{"package":{"name":"com.vaadin:vaadin-bom","ecosystem":"Maven","purl":"pkg:maven/com.vaadin/vaadin-bom"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"19.0.0"},{"fixed":"19.0.1"}]}],"versions":["19.0.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/04/GHSA-9h6g-6mxg-vvp4/GHSA-9h6g-6mxg-vvp4.json"}},{"package":{"name":"com.vaadin:vaadin-bom","ecosystem":"Maven","purl":"pkg:maven/com.vaadin/vaadin-bom"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"15.0.0"},{"fixed":"18.0.7"}]}],"versions":["15.0.0","15.0.1","15.0.2","15.0.3","15.0.4","15.0.5","15.0.6","16.0.0","16.0.1","16.0.2","16.0.3","16.0.4","16.0.5","17.0.0","17.0.1","17.0.10","17.0.11","17.0.2","17.0.3","17.0.4","17.0.6","17.0.7","17.0.8","17.0.9","18.0.0","18.0.1","18.0.2","18.0.3","18.0.4","18.0.5","18.0.6"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/04/GHSA-9h6g-6mxg-vvp4/GHSA-9h6g-6mxg-vvp4.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"}]}