445
VMScore

CVE-2022-29567

Published: 24/05/2022 Updated: 07/06/2022
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The default configuration of a TreeGrid component uses Object::toString as a key on the client-side and server communication in Vaadin 14.8.5 up to and including 14.8.9, 22.0.6 up to and including 22.0.14, 23.0.0.beta2 up to and including 23.0.8 and 23.1.0.alpha1 up to and including 23.1.0.alpha4, resulting in potential information disclosure of values that should not be available on the client-side.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

vaadin vaadin 23.0.0

vaadin vaadin

vaadin vaadin 23.1.0