Unsafe validation RegEx in EmailValidator class in com.vaadin:vaadin-server versions 7.0.0 through 7.7.21 (Vaadin 7.0.0 through 7.7.21) allows attackers to cause uncontrolled resource consumption by submitting malicious email addresses.
The product does not properly control the allocation and maintenance of a limited resource.
Link | Tags |
---|---|
https://vaadin.com/security/cve-2020-36320 | vendor advisory |
https://github.com/vaadin/framework/issues/7757 | patch third party advisory exploit |
https://github.com/vaadin/framework/pull/12104 | third party advisory patch |