Vulnerability Description
Unsafe validation RegEx in EmailField component in com.vaadin:vaadin-text-field-flow versions 2.0.4 through 2.3.2 (Vaadin 14.0.6 through 14.4.3), and 3.0.0 through 4.0.2 (Vaadin 15.0.0 through 17.0.10) allows attackers to cause uncontrolled resource consumption by submitting malicious email addresses.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Vaadin | Flow | >= 2.0.4, < 2.3.3 |
| Vaadin | Vaadin | >= 14.0.6, < 14.4.4 |
Related Weaknesses (CWE)
References
- https://github.com/vaadin/flow-components/pull/442PatchThird Party Advisory
- https://vaadin.com/security/cve-2021-31405Vendor Advisory
- https://github.com/vaadin/flow-components/pull/442PatchThird Party Advisory
- https://vaadin.com/security/cve-2021-31405Vendor Advisory
FAQ
What is CVE-2021-31405?
CVE-2021-31405 is a vulnerability with a CVSS score of 7.5 (HIGH). Unsafe validation RegEx in EmailField component in com.vaadin:vaadin-text-field-flow versions 2.0.4 through 2.3.2 (Vaadin 14.0.6 through 14.4.3), and 3.0.0 through 4.0.2 (Vaadin 15.0.0 through 17.0.10...
How severe is CVE-2021-31405?
CVE-2021-31405 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-31405?
Check the references section above for vendor advisories and patch information. Affected products include: Vaadin Flow, Vaadin Vaadin.