CVE-2020-36320: Regular expression Denial of Service (ReDoS) in EmailValidator class in Vaadin 7
Unsafe validation RegEx in EmailValidator class in com.vaadin:vaadin-server versions 7.0.0 through 7.7.21 (Vaadin 7.0.0 through 7.7.21) allows attackers to cause uncontrolled resource consumption by submitting malicious email addresses.
- https://vaadin.com/security/cve-2020-36320
Other sources
Unsafe validation RegEx in EmailValidator class in com.vaadin:vaadin-server versions 7.0.0 through 7.7.21 (Vaadin 7.0.0 through 7.7.21) allows attackers to cause uncontrolled resource consumption by submitting malicious email addresses.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-36320?
CVE-2020-36320 has a severity rating that indicates potential for resource exhaustion attacks due to unsafe RegEx validation in the EmailValidator class.
How do I fix CVE-2020-36320?
To remediate CVE-2020-36320, update to Vaadin 7 version 7.7.22 or later.
What types of attacks does CVE-2020-36320 allow?
CVE-2020-36320 allows attackers to exploit the vulnerability by submitting maliciously crafted email addresses that can lead to uncontrolled resource consumption.
Which versions of Vaadin are affected by CVE-2020-36320?
CVE-2020-36320 affects Vaadin versions from 7.0.0 up to 7.7.21.
Is there a known fix for CVE-2020-36320?
Yes, the recommended fix for CVE-2020-36320 is to upgrade to version 7.7.22 of the Vaadin framework.