CVE-2020-36319: Potential sensitive data exposure in applications using Vaadin 15
Published Apr 23, 2021
·Updated
Insecure configuration of default ObjectMapper in com.vaadin:flow-server versions 3.0.0 through 3.0.5 (Vaadin 15.0.0 through 15.0.4) may expose sensitive data if the application also uses e.g. @RestController
Affected Software
2 affected components
Vaadin flow>=3.0.0<3.0.6
Vaadin Vaadin>=15.0.0<15.0.5
Remediation
Patch Available
Patch Available
Event History
Apr 23, 2021
CVE Published
via MITRE·04:05 PM
Data Sourced
via MITRE·04:05 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-36319?
CVE-2020-36319 is classified as a medium severity vulnerability.
2
How do I fix CVE-2020-36319?
To fix CVE-2020-36319, upgrade to Vaadin Flow version 3.0.6 or higher and ensure sensitive data is not exposed through misconfigurations.
3
Who is affected by CVE-2020-36319?
CVE-2020-36319 affects users of Vaadin Flow versions 3.0.0 to 3.0.5 and Vaadin versions 15.0.0 to 15.0.4.
4
What types of applications are vulnerable to CVE-2020-36319?
Applications that use the default ObjectMapper configuration in conjunction with @RestController are vulnerable to CVE-2020-36319.
5
What data is at risk with CVE-2020-36319?
CVE-2020-36319 may expose sensitive data if the default ObjectMapper configuration is insecure.