CVE-2021-31408
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
23/04/2021
Last modified:
04/05/2021
Description
Authentication.logout() helper in com.vaadin:flow-client versions 5.0.0 prior to 6.0.0 (Vaadin 18), and 6.0.0 through 6.0.4 (Vaadin 19.0.0 through 19.0.3) uses incorrect HTTP method, which, in combination with Spring Security CSRF protection, allows local attackers to access Fusion endpoints after the user attempted to log out.
Impact
Base Score 3.x
7.10
Severity 3.x
HIGH
Base Score 2.0
3.30
Severity 2.0
LOW
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:vaadin:flow:*:*:*:*:*:*:*:* | 5.0.0 (including) | 6.0.0 (excluding) |
| cpe:2.3:a:vaadin:flow:*:*:*:*:*:*:*:* | 6.0.0 (including) | 6.0.5 (excluding) |
| cpe:2.3:a:vaadin:vaadin:*:*:*:*:*:*:*:* | 19.0.0 (including) | 19.0.4 (excluding) |
| cpe:2.3:a:vaadin:vaadin:18.0.0:-:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



