6.5
CVSSv3

CVE-2023-25499

Published: 22/06/2023 Updated: 30/06/2023
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

When adding non-visible components to the UI in server side, content is sent to the browser in Vaadin 10.0.0 up to and including 10.0.22, 11.0.0 up to and including 14.10.0, 15.0.0 up to and including 22.0.28, 23.0.0 up to and including 23.3.12, 24.0.0 up to and including 24.0.5 and 24.1.0.alpha1 to 24.1.0.beta1, resulting in potential information disclosure.

Vulnerable Product Search on Vulmon Subscribe to Product

vaadin vaadin 24.1.0

vaadin vaadin