CVE Database
/

CVE-2022-29567

Back to search

CVE-2022-29567

Published: May 24, 2022

Modified: Sep 16, 2024

PUBLISHED

CVSS v3.1

5.7

MEDIUM

Description

The default configuration of a TreeGrid component uses Object::toString as a key on the client-side and server communication in Vaadin 14.8.5 through 14.8.9, 22.0.6 through 22.0.14, 23.0.0.beta2 through 23.0.8 and 23.1.0.alpha1 through 23.1.0.alpha4, resulting in potential information disclosure of values that should not be available on the client-side.

VendorProductVersions

Vaadin

vaadin

affected
14.8.5 - < unspecified
affected
unspecified - <= 14.8.9
affected
22.0.6 - < unspecified
affected
unspecified - <= 22.0.14
affected
23.0.0.beta2 - < unspecified

+3 more versions

Vaadin

vaadin-grid-flow

affected
14.8.5 - < unspecified
affected
unspecified - <= 14.8.9
affected
22.0.6 - < unspecified
affected
unspecified - <= 22.0.14
affected
23.0.0.beta2 - < unspecified

+3 more versions

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N

Attack Vector

Network

Attack Complexity

Low

Privileges Required

Low

User Interaction

Required

Scope

Unchanged

Confidentiality

High

Integrity

None

Availability

None

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now