← Back

CVE-2022-29567

nvd nist
Published: May 24, 2022Modified: Jun 17, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

The default configuration of a TreeGrid component uses Object::toString as a key on the client-side and server communication in Vaadin 14.8.5 through 14.8.9, 22.0.6 through 22.0.14, 23.0.0.beta2 through 23.0.8 and 23.1.0.alpha1 through 23.1.0.alpha4, resulting in potential information disclosure of values that should not be available on the client-side.

Affected (12)

Products: Vaadin: Vaadin
1 product
Vaadin
Configuration A
12 vulnerable
Vulnerable SoftwareAffected Versions
Vaadin
From 14.8.5 to 14.8.9
From 22.0.6 to 22.0.15
From 23.0.1 to 23.0.8
Version 23.0.0
Version 23.0.0 beta2
Version 23.0.0 beta3
Version 23.0.0 beta4
Version 23.0.0 rc1
Version 23.1.0 alpha1
Version 23.1.0 alpha2
Version 23.1.0 alpha3
Version 23.1.0 alpha4

References (4)

Source: security@vaadin.com
Issue TrackingPatchThird Party Advisory
Source: security@vaadin.com
Issue TrackingVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingVendor Advisory

Timeline

No history available yet.