{"id":"GHSA-jmx8-355m-8vwh","summary":"Unauthorized client-side property update in UIDL request handler in Vaadin 10 and 11","details":"Missing check in UIDL request handler in com.vaadin:flow-server versions 1.0.0 through 1.0.5 (Vaadin 10.0.0 through 10.0.7, and 11.0.0 through 11.0.2) allows attacker to update element property values via crafted synchronization message.\n\n- https://vaadin.com/security/cve-2018-25007","aliases":["CVE-2018-25007"],"modified":"2023-11-08T04:00:14.726765Z","published":"2021-04-19T14:53:09Z","database_specific":{"nvd_published_at":"2021-04-23T16:15:00Z","cwe_ids":["CWE-754"],"severity":"LOW","github_reviewed":true,"github_reviewed_at":"2021-04-16T23:18:28Z"},"references":[{"type":"WEB","url":"https://github.com/vaadin/flow/security/advisories/GHSA-jmx8-355m-8vwh"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2018-25007"},{"type":"WEB","url":"https://github.com/vaadin/flow/pull/4774"},{"type":"WEB","url":"https://vaadin.com/security/cve-2018-25007"}],"affected":[{"package":{"name":"com.vaadin:flow-server","ecosystem":"Maven","purl":"pkg:maven/com.vaadin/flow-server"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.0.0"},{"fixed":"1.0.6"}]}],"versions":["1.0.0","1.0.1","1.0.2","1.0.3","1.0.4","1.0.5"],"database_specific":{"last_known_affected_version_range":"\u003c= 1.0.5","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/04/GHSA-jmx8-355m-8vwh/GHSA-jmx8-355m-8vwh.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N"}]}