Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-0753 | Improper URL validation in development mode handler in com.vaadin:flow-server versions 2.0.0 through 2.4.1 (Vaadin 14.0.0 through 14.4.2), and 3.0 prior to 5.0 (Vaadin 15 prior to 18) allows attacker to request arbitrary files stored outside of intended frontend resources folder. |
Github GHSA |
GHSA-49r2-73m6-pp8f | Directory traversal in development mode handler in Vaadin 14 and 15-17 |
No history.
Status: PUBLISHED
Assigner: Vaadin
Published:
Updated: 2024-09-17T00:45:59.853Z
Reserved: 2021-04-13T00:00:00.000Z
Link: CVE-2020-36321
No data.
Status : Modified
Published: 2021-04-23T16:15:08.403
Modified: 2026-06-17T03:15:18.163
Link: CVE-2020-36321
No data.
OpenCVE Enrichment
No data.
-
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
EUVD
Github GHSA