{"id":"GHSA-qrg9-f472-qwfm","summary":"Possible route enumeration in production mode via RouteNotFoundError view in Vaadin 10, 11-14, and 15-19","details":"Improper sanitization of path in default `RouteNotFoundError` view in `com.vaadin:flow-server` versions 1.0.0 through 1.0.14 (Vaadin 10.0.0 through 10.0.18), 1.1.0 prior to 2.0.0 (Vaadin 11 prior to 14), 2.0.0 through 2.6.1 (Vaadin 14.0.0 through 14.6.1), and 3.0.0 through 6.0.9 (Vaadin 15.0.0 through 19.0.8) allows network attacker to enumerate all available routes via crafted HTTP request when application is running in production mode and no custom handler for `NotFoundException` is provided.\n\n- https://vaadin.com/security/cve-2021-31412","aliases":["CVE-2021-31412"],"modified":"2023-11-08T04:05:48.650539Z","published":"2021-06-28T16:55:58Z","database_specific":{"nvd_published_at":"2021-06-24T12:15:00Z","cwe_ids":["CWE-1295","CWE-20","CWE-668"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2021-06-24T19:46:19Z"},"references":[{"type":"WEB","url":"https://github.com/vaadin/platform/security/advisories/GHSA-qrg9-f472-qwfm"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-31412"},{"type":"WEB","url":"https://github.com/vaadin/flow/pull/11107"},{"type":"WEB","url":"https://vaadin.com/security/cve-2021-31412"}],"affected":[{"package":{"name":"com.vaadin:vaadin-bom","ecosystem":"Maven","purl":"pkg:maven/com.vaadin/vaadin-bom"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"10.0.0"},{"fixed":"10.0.19"}]}],"versions":["10.0.0","10.0.1","10.0.10","10.0.11","10.0.12","10.0.13","10.0.14","10.0.15","10.0.16","10.0.17","10.0.18","10.0.2","10.0.3","10.0.4","10.0.5","10.0.6","10.0.7","10.0.8","10.0.9"],"database_specific":{"last_known_affected_version_range":"\u003c= 10.0.18","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/06/GHSA-qrg9-f472-qwfm/GHSA-qrg9-f472-qwfm.json"}},{"package":{"name":"com.vaadin:vaadin-bom","ecosystem":"Maven","purl":"pkg:maven/com.vaadin/vaadin-bom"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"11.0.0"},{"fixed":"14.6.2"}]}],"versions":["11.0.0","11.0.1","11.0.2","11.0.3","11.0.4","12.0.0","12.0.1","12.0.2","12.0.3","12.0.4","12.0.5","12.0.6","12.0.7","13.0.0","13.0.1","13.0.10","13.0.11","13.0.12","13.0.13","13.0.2","13.0.3","13.0.4","13.0.5","13.0.6","13.0.7","13.0.8","13.0.9","14.0.0","14.0.1","14.0.10","14.0.11","14.0.12","14.0.13","14.0.14","14.0.15","14.0.2","14.0.3","14.0.4","14.0.5","14.0.6","14.0.7","14.0.8","14.0.9","14.1.0","14.1.1","14.1.16","14.1.17","14.1.18","14.1.19","14.1.2","14.1.20","14.1.21","14.1.22","14.1.23","14.1.24","14.1.25","14.1.26","14.1.27","14.1.28","14.1.3","14.1.4","14.1.5","14.2.0","14.2.1","14.2.2","14.2.3","14.3.0","14.3.1","14.3.2","14.3.3","14.3.4","14.3.5","14.3.6","14.3.7","14.3.8","14.3.9","14.4.0","14.4.1","14.4.10","14.4.2","14.4.3","14.4.4","14.4.5","14.4.6","14.4.7","14.4.8","14.4.9","14.5.0","14.5.1","14.5.2","14.5.3","14.5.4","14.5.5","14.6.0","14.6.1"],"database_specific":{"last_known_affected_version_range":"\u003c 14.0.0","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/06/GHSA-qrg9-f472-qwfm/GHSA-qrg9-f472-qwfm.json"}},{"package":{"name":"com.vaadin:vaadin-bom","ecosystem":"Maven","purl":"pkg:maven/com.vaadin/vaadin-bom"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"15.0.0"},{"fixed":"19.0.9"}]}],"versions":["15.0.0","15.0.1","15.0.2","15.0.3","15.0.4","15.0.5","15.0.6","16.0.0","16.0.1","16.0.2","16.0.3","16.0.4","16.0.5","17.0.0","17.0.1","17.0.10","17.0.11","17.0.2","17.0.3","17.0.4","17.0.6","17.0.7","17.0.8","17.0.9","18.0.0","18.0.1","18.0.2","18.0.3","18.0.4","18.0.5","18.0.6","18.0.7","19.0.0","19.0.1","19.0.2","19.0.3","19.0.4","19.0.5","19.0.6","19.0.7","19.0.8"],"database_specific":{"last_known_affected_version_range":"\u003c= 19.0.8","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/06/GHSA-qrg9-f472-qwfm/GHSA-qrg9-f472-qwfm.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"}]}