← Back

CVE-2021-33605

nvd nist
Published: Aug 25, 2021Modified: Nov 21, 2024

JSON object

Loading...
4.3
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Exploitability: 2.8 / Impact: 1.4
Source: NVD

Description

Improper check in CheckboxGroup in com.vaadin:vaadin-checkbox-flow versions 1.2.0 prior to 2.0.0 (Vaadin 12.0.0 prior to 14.0.0), 2.0.0 prior to 3.0.0 (Vaadin 14.0.0 prior to 14.5.0), 3.0.0 through 4.0.1 (Vaadin 15.0.0 through 17.0.11), 14.5.0 through 14.6.7 (Vaadin 14.5.0 through 14.6.7), and 18.0.0 through 20.0.5 (Vaadin 18.0.0 through 20.0.5) allows attackers to modify the value of a disabled Checkbox inside enabled CheckboxGroup component via unspecified vectors.

Affected (5)

1 product
Vaadin Checkbox Flow
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 1.2.0 to 2.0.0
Running on/withPlatform Versions
Vaadin
Vaadin
From 12.0.0 to 14.0.0
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 2.0.0 to 3.0.0
Running on/withPlatform Versions
Vaadin
Vaadin
From 14.0.0 to 14.5.0
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 3.0.0 to 4.0.1
Running on/withPlatform Versions
Vaadin
Vaadin
From 15.0.0 to 17.0.11
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 14.5.0 to 14.6.7
Running on/withPlatform Versions
Vaadin
Vaadin
From 14.5.0 to 14.6.7
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 18.0.0 to 20.0.5
Running on/withPlatform Versions
Vaadin
Vaadin
From 18.0.0 to 20.0.5

References (4)

Source: security@vaadin.com
PatchThird Party Advisory
Source: security@vaadin.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.