CVE-2023-25500
בינונית 4.3
תיאור (מקור, אנגלית)
Possible information disclosure in Vaadin 10.0.0 to 10.0.23, 11.0.0 to 14.10.1, 15.0.0 to 22.0.28, 23.0.0 to 23.3.13, 24.0.0 to 24.0.6, 24.1.0.alpha1 to 24.1.0.rc2, resulting in potential information disclosure of class and method names in RPC responses by sending modified requests.
מדדים
- CVSS 3.1
-
4.3 (MEDIUM)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N - EPSS — סבירות ניצול
- 1% (אחוזון 000) נכון ל-9/10/2026
- CWE
- CWE-200
מוצרים מושפעים
vaadin: vaadin
קישורים
- https://vaadin.com/security/cve-2023-25500 Vendor Advisory
- https://vaadin.com/security/cve-2023-25500 Vendor Advisory
- https://github.com/vaadin/flow/pull/16935 Patch
- https://github.com/vaadin/flow/pull/16935 Patch