CVE-2021-31411: Insecure temporary directory usage in frontend build functionality of Vaadin 14 and 15-19
Insecure temporary directory usage in frontend build functionality of com.vaadin:flow-server versions 2.0.9 through 2.5.2 (Vaadin 14.0.3 through Vaadin 14.5.2), 3.0 prior to 6.0 (Vaadin 15 prior to 19), and 6.0.0 through 6.0.5 (Vaadin 19.0.0 through 19.0.4) allows local users to inject malicious code into frontend resources during application rebuilds.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-31411?
CVE-2021-31411 has been classified as a medium severity vulnerability due to insecure temporary directory usage.
How do I fix CVE-2021-31411?
To fix CVE-2021-31411, update Vaadin Flow server to version 2.5.3 or later, 3.0.0 or later, and 6.0.6 or later.
Who is affected by CVE-2021-31411?
CVE-2021-31411 affects Vaadin Flow server versions from 2.0.9 to 2.5.2, 3.0 prior to 6.0, and 6.0.0 to 6.0.5, as well as specific versions of Vaadin 14 and Vaadin 15.
What impact does CVE-2021-31411 have?
The impact of CVE-2021-31411 allows local users to inject code through insecure handling of temporary directories.
Is CVE-2021-31411 publicly known?
Yes, CVE-2021-31411 was publicly disclosed and listed in the Common Vulnerabilities and Exposures database.