{"id":"GHSA-c6c4-7x48-4cqp","summary":"Timing side channel vulnerability in UIDL request handler in Vaadin 10, 11-14, and 15-18","details":"Non-constant-time comparison of CSRF tokens in UIDL request handler in `com.vaadin:flow-server` versions 1.0.0 through 1.0.13 (Vaadin 10.0.0 through 10.0.16), 1.1.0 prior to 2.0.0 (Vaadin 11 prior to 14), 2.0.0 through 2.4.6 (Vaadin 14.0.0 through 14.4.6), 3.0.0 prior to 5.0.0 (Vaadin 15 prior to 18), and 5.0.0 through 5.0.2 (Vaadin 18.0.0 through 18.0.5) allows attacker to guess a security token via timing attack.\n\n- https://vaadin.com/security/cve-2021-31404","modified":"2024-12-02T05:39:52.682940Z","published":"2021-04-19T14:47:47Z","database_specific":{"github_reviewed_at":"2021-04-16T23:13:25Z","nvd_published_at":null,"cwe_ids":["CWE-208"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/vaadin/platform/security/advisories/GHSA-c6c4-7x48-4cqp"},{"type":"PACKAGE","url":"https://github.com/vaadin/platform"},{"type":"WEB","url":"https://vaadin.com/security/cve-2021-31404"}],"affected":[{"package":{"name":"com.vaadin:vaadin-bom","ecosystem":"Maven","purl":"pkg:maven/com.vaadin/vaadin-bom"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"10.0.0"},{"fixed":"10.0.17"}]}],"versions":["10.0.0","10.0.1","10.0.10","10.0.11","10.0.12","10.0.13","10.0.14","10.0.15","10.0.16","10.0.2","10.0.3","10.0.4","10.0.5","10.0.6","10.0.7","10.0.8","10.0.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/04/GHSA-c6c4-7x48-4cqp/GHSA-c6c4-7x48-4cqp.json"}},{"package":{"name":"com.vaadin:vaadin-bom","ecosystem":"Maven","purl":"pkg:maven/com.vaadin/vaadin-bom"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"11.0.0"},{"fixed":"14.4.7"}]}],"versions":["11.0.0","11.0.1","11.0.2","11.0.3","11.0.4","12.0.0","12.0.1","12.0.2","12.0.3","12.0.4","12.0.5","12.0.6","12.0.7","13.0.0","13.0.1","13.0.10","13.0.11","13.0.12","13.0.13","13.0.2","13.0.3","13.0.4","13.0.5","13.0.6","13.0.7","13.0.8","13.0.9","14.0.0","14.0.1","14.0.10","14.0.11","14.0.12","14.0.13","14.0.14","14.0.15","14.0.2","14.0.3","14.0.4","14.0.5","14.0.6","14.0.7","14.0.8","14.0.9","14.1.0","14.1.1","14.1.16","14.1.17","14.1.18","14.1.19","14.1.2","14.1.20","14.1.21","14.1.22","14.1.23","14.1.24","14.1.25","14.1.26","14.1.27","14.1.28","14.1.3","14.1.4","14.1.5","14.2.0","14.2.1","14.2.2","14.2.3","14.3.0","14.3.1","14.3.2","14.3.3","14.3.4","14.3.5","14.3.6","14.3.7","14.3.8","14.3.9","14.4.0","14.4.1","14.4.2","14.4.3","14.4.4","14.4.5","14.4.6"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/04/GHSA-c6c4-7x48-4cqp/GHSA-c6c4-7x48-4cqp.json"}},{"package":{"name":"com.vaadin:vaadin-bom","ecosystem":"Maven","purl":"pkg:maven/com.vaadin/vaadin-bom"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"15.0.0"},{"fixed":"18.0.6"}]}],"versions":["15.0.0","15.0.1","15.0.2","15.0.3","15.0.4","15.0.5","15.0.6","16.0.0","16.0.1","16.0.2","16.0.3","16.0.4","16.0.5","17.0.0","17.0.1","17.0.10","17.0.11","17.0.2","17.0.3","17.0.4","17.0.6","17.0.7","17.0.8","17.0.9","18.0.0","18.0.1","18.0.2","18.0.3","18.0.4","18.0.5"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/04/GHSA-c6c4-7x48-4cqp/GHSA-c6c4-7x48-4cqp.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"}]}