CVE-2019-25027

Description

Missing output sanitization in default RouteNotFoundError view in com.vaadin:flow-server versions 1.0.0 through 1.0.10 (Vaadin 10.0.0 through 10.0.13), and 1.1.0 through 1.4.2 (Vaadin 11.0.0 through 13.0.5) allows attacker to execute malicious JavaScript via crafted URL

Risk Information

Base Score
6.1
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS Score
Exploitation Probability
0.371

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2019-25027 are fixed in Vaadin-flow-server 1.0.11Windows
Vulnerabilities CVE-2019-25027 are fixed in Vaadin-flow-server 1.4.3Windows
Vulnerabilities CVE-2019-25027 are fixed in Vaadin-flow-server for Linux 1.0.11Linux
Vulnerabilities CVE-2019-25027 are fixed in Vaadin-flow-server for Linux 1.4.3Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234