CVE-2021-31409: Server session is not invalidated when logout() helper method of Authentication module is used in Vaadin 18-19
Unsafe validation RegEx in EmailValidator component in com.vaadin:vaadin-compatibility-server versions 8.0.0 through 8.12.4 (Vaadin versions 8.0.0 through 8.12.4) allows attackers to cause uncontrolled resource consumption by submitting malicious email addresses.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-31409?
CVE-2021-31409 has a medium severity rating due to its potential to cause resource exhaustion through malicious email submissions.
How do I fix CVE-2021-31409?
To fix CVE-2021-31409, upgrade to Vaadin version 8.12.5 or later where the validation issue has been addressed.
What products are affected by CVE-2021-31409?
CVE-2021-31409 affects com.vaadin:vaadin-compatibility-server versions from 8.0.0 to 8.12.4.
What kind of attack can be performed using CVE-2021-31409?
Attackers can leverage CVE-2021-31409 to submit crafted email addresses that may lead to denial of service through resource consumption.
Is there a workaround for CVE-2021-31409?
There is no specific workaround for CVE-2021-31409, so upgrading to a secure version is essential.