Skip to main content

Transmission of Private Resources into a New Sphere ('Resource Leak')

CVE-2021-31410

Severity High
Score 8.6/10

Summary

Overly relaxed configuration of frontend resources server in Vaadin Designer versions 4.3.0 through 4.6.3 allows remote attackers to access project sources via crafted HTTP request.

  • LOW
  • NETWORK
  • NONE
  • CHANGED
  • NONE
  • NONE
  • HIGH
  • NONE

CWE-402 - Transmission of Private Resources into a New Sphere ('Resource Leak')

The software makes resources available to untrusted parties when those resources are only intended to be accessed by the software.

References

Advisory Timeline

  • Published