Unsafe validation RegEx in EmailValidator component in com.vaadin:vaadin-compatibility-server versions 8.0.0 through 8.12.4 (Vaadin versions 8.0.0 through 8.12.4) allows attackers to cause uncontrolled resource consumption by submitting malicious email addresses.
The product does not properly control the allocation and maintenance of a limited resource.
Link | Tags |
---|---|
https://vaadin.com/security/cve-2021-31409 | vendor advisory |
https://github.com/vaadin/framework/issues/12240 | third party advisory patch |
https://github.com/vaadin/framework/pull/12241 | third party advisory patch |