CVE-2021-33611: Reflected cross-site scripting in vaadin-menu-bar webjar resources in Vaadin 14
Missing output sanitization in test sources in org.webjars.bowergithub.vaadin:vaadin-menu-bar versions 1.0.0 through 1.2.0 (Vaadin 14.0.0 through 14.4.4) allows remote attackers to execute malicious JavaScript in browser by opening crafted URL
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-33611?
CVE-2021-33611 is classified as a high-severity vulnerability due to the potential for remote JavaScript execution.
How do I fix CVE-2021-33611?
To fix CVE-2021-33611, users should upgrade to vaadin-menu-bar version 1.2.1 or later and vaadin version 14.4.5 or later.
What versions are affected by CVE-2021-33611?
CVE-2021-33611 affects vaadin-menu-bar versions 1.0.0 through 1.2.0 and Vaadin versions 14.0.0 through 14.4.4.
What type of attack does CVE-2021-33611 enable?
CVE-2021-33611 enables remote attackers to execute arbitrary JavaScript in users' browsers through crafted URLs.
Is user interaction required to exploit CVE-2021-33611?
Yes, exploitation of CVE-2021-33611 requires user interaction to click on a malicious link.