CVE-2021-31405: Regular expression denial of service (ReDoS) in EmailField component in Vaadin 14 and 15-17
Published Apr 23, 2021
·Updated
Unsafe validation RegEx in EmailField component in com.vaadin:vaadin-text-field-flow versions 2.0.4 through 2.3.2 (Vaadin 14.0.6 through 14.4.3), and 3.0.0 through 4.0.2 (Vaadin 15.0.0 through 17.0.10) allows attackers to cause uncontrolled resource consumption by submitting malicious email addresses.
Affected Software
4 affected components
Vaadin flow>=2.0.4<2.3.3
Vaadin flow>=3.0.0<4.0.3
Vaadin Vaadin>=14.0.6<14.4.4
Vaadin Vaadin>=15.0.0<17.0.11
Remediation
Patch Available
Event History
Apr 23, 2021
CVE Published
via MITRE·04:05 PM
Data Sourced
via MITRE·04:05 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-31405?
The severity of CVE-2021-31405 is high with a CVSS score of 7.5.
2
How to fix CVE-2021-31405?
To fix CVE-2021-31405, users should upgrade to versions 2.3.3 or higher for Vaadin Flow versions 2.0.4 through 2.3.2, and upgrade to versions 4.0.3 or higher for Vaadin Flow versions 3.0.0 through 4.0.2.