Vulnerability Description
Overly relaxed configuration of frontend resources server in Vaadin Designer versions 4.3.0 through 4.6.3 allows remote attackers to access project sources via crafted HTTP request.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Vaadin | Designer | >= 4.3.0, < 4.6.4 |
Related Weaknesses (CWE)
References
- https://vaadin.com/security/cve-2021-31410Vendor Advisory
- https://vaadin.com/security/cve-2021-31410Vendor Advisory
FAQ
What is CVE-2021-31410?
CVE-2021-31410 is a vulnerability with a CVSS score of 8.6 (HIGH). Overly relaxed configuration of frontend resources server in Vaadin Designer versions 4.3.0 through 4.6.3 allows remote attackers to access project sources via crafted HTTP request.
How severe is CVE-2021-31410?
CVE-2021-31410 has been rated HIGH with a CVSS base score of 8.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-31410?
Check the references section above for vendor advisories and patch information. Affected products include: Vaadin Designer.