CVE-2021-33609: Denial of service in DataCommunicator class in Vaadin 8
Missing check in DataCommunicator class in com.vaadin:vaadin-server versions 8.0.0 through 8.14.0 (Vaadin 8.0.0 through 8.14.0) allows authenticated network attacker to cause heap exhaustion by requesting too many rows of data.
Other sources
Missing check in DataCommunicator class in com.vaadin:vaadin-server versions 8.0.0 through 8.14.0 (Vaadin 8.0.0 through 8.14.0) allows authenticated network attacker to cause heap exhaustion by requesting too many rows of data.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-33609?
The severity of CVE-2021-33609 is classified as medium, as it allows authenticated attackers to exhaust heap memory by requesting excessive data.
What versions are affected by CVE-2021-33609?
CVE-2021-33609 affects versions 8.0.0 through 8.14.0 of Vaadin's vaadin-server.
How do I fix CVE-2021-33609?
To fix CVE-2021-33609, upgrade to version 8.14.1 of com.vaadin:vaadin-server.
What kind of attack does CVE-2021-33609 facilitate?
CVE-2021-33609 allows authenticated attackers to perform a denial of service attack by causing heap exhaustion.
Which component is affected in CVE-2021-33609?
CVE-2021-33609 specifically affects the DataCommunicator class in the com.vaadin:vaadin-server package.