CVE-2023-25499: Possible information disclosure in non visible components
Description When adding non-visible components to the UI in server side, content is sent to the browser in Vaadin 10.0.0 through 10.0.22, 11.0.0 through 14.10.0, 15.0.0 through 22.0.28, 23.0.0 through 23.3.12, 24.0.0 through 24.0.5 and 24.1.0.alpha1 to 24.1.0.beta1, resulting in potential information disclosure.
https://vaadin.com/security/cve-2023-25499
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2023-25499?
CVE-2023-25499 is classified as a high severity vulnerability due to the potential for unauthorized access to sensitive information.
How do I fix CVE-2023-25499?
To mitigate CVE-2023-25499, upgrade to a non-vulnerable version of the Vaadin framework, such as 24.1.0, 24.0.8, or appropriate versions for Vaadin 23, 14, 10, and 2.
Which versions of Vaadin are affected by CVE-2023-25499?
CVE-2023-25499 affects Vaadin versions from 10.0.0 to 24.0.5 and specific pre-release versions of 24.1.0.
What are the risks associated with CVE-2023-25499?
The risks associated with CVE-2023-25499 include exposure of non-visible components and sensitive data being sent to the browser.
How can I identify if my Vaadin application is vulnerable to CVE-2023-25499?
You can identify vulnerability to CVE-2023-25499 by checking your application’s Vaadin version against the listed affected versions and testing for data exposure.