CVE-2021-33604: Reflected cross-site scripting in development mode handler in Vaadin 14, 15-19
URL encoding error in development mode handler in com.vaadin:flow-server versions 2.0.0 through 2.6.1 (Vaadin 14.0.0 through 14.6.1), 3.0.0 through 6.0.9 (Vaadin 15.0.0 through 19.0.8) allows local user to execute arbitrary JavaScript code by opening crafted URL in browser.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability CVE-2021-33604?
CVE-2021-33604 is a URL encoding error in the development mode handler of Vaadin Flow that allows local users to execute arbitrary JavaScript code via crafted URLs.
What is the severity of CVE-2021-33604?
CVE-2021-33604 has a high severity rating due to its potential to allow script injection and unauthorized code execution.
How do I fix CVE-2021-33604?
To fix CVE-2021-33604, update your Vaadin Flow Server version to a secure release that is above the vulnerable versions.
Which versions are affected by CVE-2021-33604?
CVE-2021-33604 affects Vaadin Flow versions 2.0.0 through 2.6.1 and 3.0.0 through 6.0.9, as well as Vaadin versions from 14.0.0 through 19.0.8.
Who is impacted by CVE-2021-33604?
Developers and users running affected versions of Vaadin Flow in development environments are impacted by CVE-2021-33604.