Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2018-25007— Unauthorized client-side property update in UIDL request handler in Vaadin 10 and 11

CVSS 2.6 · Low EPSS 0.29% · P52
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2018-25007

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Unauthorized client-side property update in UIDL request handler in Vaadin 10 and 11
Source: NVD (National Vulnerability Database)
Vulnerability Description
Missing check in UIDL request handler in com.vaadin:flow-server versions 1.0.0 through 1.0.5 (Vaadin 10.0.0 through 10.0.7, and 11.0.0 through 11.0.2) allows attacker to update element property values via crafted synchronization message.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N
Source: NVD (National Vulnerability Database)
Vulnerability Type
对因果或异常条件的不恰当检查
Source: NVD (National Vulnerability Database)
Vulnerability Title
Vaadin flow 代码问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Vaadin flow是一个应用软件。Vaadin平台的Java框架,用于构建外观美观,性能良好并让您和您的用户感到满意的现代网站。 vaadin:flow-server versions 1.0.0版本至1.0.5版本存在代码问题漏洞,该漏洞源于UIDL请求处理程序中缺少检查。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
VaadinVaadin 10.0.0 ~ * -
Vaadinflow-server 1.0.0 ~ * -

II. Public POCs for CVE-2018-25007

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2018-25007

Please Login to view more intelligence information

Same Patch Batch · Vaadin · 2021-04-23 · 13 CVEs total

CVE-2021-314078.6 HIGHServer classes and resources exposure in OSGi applications using Vaadin 12-14 and 19
CVE-2021-314108.6 HIGHProject sources exposure in Vaadin Designer
CVE-2020-363207.5 HIGHRegular expression Denial of Service (ReDoS) in EmailValidator class in Vaadin 7
CVE-2021-314057.5 HIGHRegular expression denial of service (ReDoS) in EmailField component in Vaadin 14 and 15-1
CVE-2021-314086.3 MEDIUMServer session is not invalidated when logout() helper method of Authentication module is
CVE-2019-250276.1 MEDIUMReflected cross-site scripting in default RouteNotFoundError view in Vaadin 10 and 11-13
CVE-2020-363215.9 MEDIUMDirectory traversal in development mode handler in Vaadin 14 and 15-17
CVE-2019-250285.4 MEDIUMStored cross-site scripting in Grid component in Vaadin 7 and 8
CVE-2021-314034.0 MEDIUMTiming side channel vulnerability in UIDL request handler in Vaadin 7 and 8
CVE-2021-314044.0 MEDIUMTiming side channel vulnerability in UIDL request handler in Vaadin 10, 11-14, and 15-18
CVE-2021-314064.0 MEDIUMTiming side channel vulnerability in endpoint request handler in Vaadin 15-19
CVE-2020-363193.1 LOWPotential sensitive data exposure in applications using Vaadin 15

IV. Related Vulnerabilities

V. Comments for CVE-2018-25007

No comments yet


Leave a comment