CVE-2021-31404: Timing side channel vulnerability in UIDL request handler in Vaadin 10, 11-14, and 15-18
Non-constant-time comparison of CSRF tokens in UIDL request handler in com.vaadin:flow-server versions 1.0.0 through 1.0.13 (Vaadin 10.0.0 through 10.0.16), 1.1.0 prior to 2.0.0 (Vaadin 11 prior to 14), 2.0.0 through 2.4.6 (Vaadin 14.0.0 through 14.4.6), 3.0.0 prior to 5.0.0 (Vaadin 15 prior to 18), and 5.0.0 through 5.0.2 (Vaadin 18.0.0 through 18.0.5) allows attacker to guess a security token via timing attack.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-31404?
CVE-2021-31404 has been classified with a moderate severity level due to its potential exploitation in CSRF attacks.
How do I fix CVE-2021-31404?
To fix CVE-2021-31404, update the affected Vaadin Flow versions to 1.0.14, 2.0.0, 2.4.7, or 5.0.0 and later.
Which versions are affected by CVE-2021-31404?
CVE-2021-31404 affects Vaadin Flow versions 1.0.0 to 1.0.13, 1.1.0 prior to 2.0.0, 2.0.0 to 2.4.6, and 3.0.0 prior to 5.0.0.
What type of vulnerability is CVE-2021-31404?
CVE-2021-31404 is a security vulnerability related to non-constant-time comparison of CSRF tokens.
What components are impacted by CVE-2021-31404?
The components impacted by CVE-2021-31404 include the UIDL request handler in the Vaadin Flow framework.