Overly relaxed configuration of frontend resources server in Vaadin Designer versions 4.3.0 through 4.6.3 allows remote attackers to access project sources via crafted HTTP request.
The product makes resources available to untrusted parties when those resources are only intended to be accessed by the product.
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
Link | Tags |
---|---|
https://vaadin.com/security/cve-2021-31410 | vendor advisory |