Loading HuntDB...

GHSA-49r2-73m6-pp8f

GitHub Security Advisory

Directory traversal in development mode handler in Vaadin 14 and 15-17

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

Improper URL validation in development mode handler in `com.vaadin:flow-server` versions 2.0.0 through 2.4.1 (Vaadin 14.0.0 through 14.4.2), and 3.0 prior to 5.0 (Vaadin 15 prior to 18) allows attacker to request arbitrary files stored outside of intended frontend resources folder.

- https://vaadin.com/security/cve-2020-36321

Affected Packages

Maven com.vaadin:flow-server
Affected versions: 3.0.0 (fixed in 5.0.0)
Maven com.vaadin:flow-server
Affected versions: 2.0.0 (fixed in 2.4.2)

Related CVEs

Key Information

GHSA ID
GHSA-49r2-73m6-pp8f
Published
April 19, 2021 2:51 PM
Last Modified
April 23, 2021 5:13 PM
CVSS Score
5.0 /10
Primary Ecosystem
Maven
Primary Package
com.vaadin:flow-server
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 6, 2025 6:30 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.