CVE-2021-31410: Project sources exposure in Vaadin Designer
Published Apr 23, 2021
·Updated
Overly relaxed configuration of frontend resources server in Vaadin Designer versions 4.3.0 through 4.6.3 allows remote attackers to access project sources via crafted HTTP request.
Affected Software
1 affected component
Vaadin Designer>=4.3.0<4.6.4
Event History
Apr 23, 2021
CVE Published
via MITRE·04:08 PM
Data Sourced
via MITRE·04:08 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-31410?
The severity of CVE-2021-31410 is classified as medium due to the potential for unauthorized access to project sources.
2
How do I fix CVE-2021-31410?
To fix CVE-2021-31410, upgrade Vaadin Designer to version 4.6.4 or later.
3
What versions are affected by CVE-2021-31410?
CVE-2021-31410 affects Vaadin Designer versions 4.3.0 through 4.6.3.
4
Can CVE-2021-31410 lead to data exposure?
Yes, CVE-2021-31410 may allow remote attackers to access sensitive project sources.
5
What should I do if I cannot upgrade due to dependencies for CVE-2021-31410?
If unable to upgrade, ensure to implement additional access controls to mitigate the risks associated with CVE-2021-31410.