Vulnerability Description
Insecure configuration of default ObjectMapper in com.vaadin:flow-server versions 3.0.0 through 3.0.5 (Vaadin 15.0.0 through 15.0.4) may expose sensitive data if the application also uses e.g. @RestController
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Vaadin | Flow | >= 3.0.0, < 3.0.6 |
| Vaadin | Vaadin | >= 15.0.0, < 15.0.5 |
Related Weaknesses (CWE)
References
- https://github.com/vaadin/flow/pull/8016PatchThird Party Advisory
- https://github.com/vaadin/flow/pull/8051PatchThird Party Advisory
- https://vaadin.com/security/cve-2020-36319Vendor Advisory
- https://github.com/vaadin/flow/pull/8016PatchThird Party Advisory
- https://github.com/vaadin/flow/pull/8051PatchThird Party Advisory
- https://vaadin.com/security/cve-2020-36319Vendor Advisory
FAQ
What is CVE-2020-36319?
CVE-2020-36319 is a vulnerability with a CVSS score of 3.1 (LOW). Insecure configuration of default ObjectMapper in com.vaadin:flow-server versions 3.0.0 through 3.0.5 (Vaadin 15.0.0 through 15.0.4) may expose sensitive data if the application also uses e.g. @RestCo...
How severe is CVE-2020-36319?
CVE-2020-36319 has been rated LOW with a CVSS base score of 3.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-36319?
Check the references section above for vendor advisories and patch information. Affected products include: Vaadin Flow, Vaadin Vaadin.