CVE-2020-36321: Directory traversal in development mode handler in Vaadin 14 and 15-17
Improper URL validation in development mode handler in com.vaadin:flow-server versions 2.0.0 through 2.4.1 (Vaadin 14.0.0 through 14.4.2), and 3.0 prior to 5.0 (Vaadin 15 prior to 18) allows attacker to request arbitrary files stored outside of intended frontend resources folder.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-36321?
CVE-2020-36321 is considered a high severity vulnerability due to its potential for unauthorized access to arbitrary files.
How do I fix CVE-2020-36321?
To fix CVE-2020-36321, update Vaadin Flow to version 2.4.2 or later, or version 5.0.0 or later for Vaadin 15.
What does CVE-2020-36321 exploit?
CVE-2020-36321 exploits improper URL validation in the development mode handler of Vaadin Flow.
Which versions are affected by CVE-2020-36321?
CVE-2020-36321 affects Vaadin Flow versions 2.0.0 through 2.4.1 and 3.0.0 prior to 5.0.0.
What can an attacker do with CVE-2020-36321?
An attacker can use CVE-2020-36321 to request arbitrary files stored outside of the intended frontend resources folder.