CVE-2021-31403: Timing side channel vulnerability in UIDL request handler in Vaadin 7 and 8
Published Apr 23, 2021
·Updated
Non-constant-time comparison of CSRF tokens in UIDL request handler in com.vaadin:vaadin-server versions 7.0.0 through 7.7.23 (Vaadin 7.0.0 through 7.7.23), and 8.0.0 through 8.12.2 (Vaadin 8.0.0 through 8.12.2) allows attacker to guess a security token via timing attack
Affected Software
2 affected components
Vaadin Vaadin>=7.0.0<7.7.24
Vaadin Vaadin>=8.0.0<8.12.3
Remediation
Patch Available
Patch Available
Event History
Apr 23, 2021
CVE Published
via MITRE·04:05 PM
Data Sourced
via MITRE·04:05 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2021-31403?
CVE-2021-31403 is a vulnerability that allows an attacker to guess a security token via a timing attack in the UIDL request handler in com.vaadin:vaadin-server versions 7.0.0 through 7.7.23 and 8.0.0 through 8.12.2.
2
How severe is CVE-2021-31403?
CVE-2021-31403 has a severity score of 2.5, which is considered medium.
3
How can I fix CVE-2021-31403?
To fix CVE-2021-31403, update your com.vaadin:vaadin-server version to 7.7.24 or higher for Vaadin 7, and 8.12.3 or higher for Vaadin 8.