7.5

CVE-2022-29567

The default configuration of a TreeGrid component uses Object::toString as a key on the client-side and server communication in Vaadin 14.8.5 through 14.8.9, 22.0.6 through 22.0.14, 23.0.0.beta2 through 23.0.8 and 23.1.0.alpha1 through 23.1.0.alpha4, resulting in potential information disclosure of values that should not be available on the client-side.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
VaadinVaadin Version >= 14.8.5 <= 14.8.9
VaadinVaadin Version >= 22.0.6 <= 22.0.15
VaadinVaadin Version >= 23.0.1 <= 23.0.8
VaadinVaadin Version23.0.0 Update-
VaadinVaadin Version23.0.0 Updatebeta2
VaadinVaadin Version23.0.0 Updatebeta3
VaadinVaadin Version23.0.0 Updatebeta4
VaadinVaadin Version23.0.0 Updaterc1
VaadinVaadin Version23.1.0 Updatealpha1
VaadinVaadin Version23.1.0 Updatealpha2
VaadinVaadin Version23.1.0 Updatealpha3
VaadinVaadin Version23.1.0 Updatealpha4
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.27% 0.499
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
security@vaadin.com 5.7 2.1 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.