{"id":"GHSA-jqj4-r483-4gvr","summary":"Reflected cross-site scripting in default RouteNotFoundError view in Vaadin 10 and 11-13","details":"Missing output sanitization in default `RouteNotFoundError` view in `com.vaadin:flow-server` versions 1.0.0 through 1.0.10 (Vaadin 10.0.0 through 10.0.13), and 1.1.0 through 1.4.2 (Vaadin 11.0.0 through 13.0.5) allows attacker to execute malicious JavaScript via crafted URL.\n\n- https://vaadin.com/security/cve-2019-25027","modified":"2024-12-02T05:40:30.078372Z","published":"2021-04-19T14:48:51Z","database_specific":{"github_reviewed_at":"2021-04-16T23:14:38Z","nvd_published_at":null,"cwe_ids":["CWE-81"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/vaadin/platform/security/advisories/GHSA-jqj4-r483-4gvr"},{"type":"PACKAGE","url":"https://github.com/vaadin/platform"},{"type":"WEB","url":"https://vaadin.com/security/cve-2019-25027"}],"affected":[{"package":{"name":"com.vaadin:vaadin-bom","ecosystem":"Maven","purl":"pkg:maven/com.vaadin/vaadin-bom"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"10.0.0"},{"fixed":"10.0.14"}]}],"versions":["10.0.0","10.0.1","10.0.10","10.0.11","10.0.12","10.0.13","10.0.2","10.0.3","10.0.4","10.0.5","10.0.6","10.0.7","10.0.8","10.0.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/04/GHSA-jqj4-r483-4gvr/GHSA-jqj4-r483-4gvr.json"}},{"package":{"name":"com.vaadin:vaadin-bom","ecosystem":"Maven","purl":"pkg:maven/com.vaadin/vaadin-bom"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"11.0.0"},{"fixed":"13.0.6"}]}],"versions":["11.0.0","11.0.1","11.0.2","11.0.3","11.0.4","12.0.0","12.0.1","12.0.2","12.0.3","12.0.4","12.0.5","12.0.6","12.0.7","13.0.0","13.0.1","13.0.2","13.0.3","13.0.4","13.0.5"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/04/GHSA-jqj4-r483-4gvr/GHSA-jqj4-r483-4gvr.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}