CVE-2022-29567

Possible information disclosure inside TreeGrid component with default data provider

Description

The default configuration of a TreeGrid component uses Object::toString as a key on the client-side and server communication in Vaadin 14.8.5 through 14.8.9, 22.0.6 through 22.0.14, 23.0.0.beta2 through 23.0.8 and 23.1.0.alpha1 through 23.1.0.alpha4, resulting in potential information disclosure of values that should not be available on the client-side.

Remediation

Workaround:

  • User might define either: custom `toString()` or `getId()` in their entity.

Category

5.7
CVSS
Severity: Medium
CVSS 3.1 •
CVSS 2.0 •
EPSS 0.32%
Vendor Advisory vaadin.com
Affected: Vaadin vaadin
Affected: Vaadin vaadin-grid-flow
Published at:
Updated at:

References

Link Tags
https://vaadin.com/security/cve-2022-29567 vendor advisory issue tracking
https://github.com/vaadin/flow-components/pull/3046 patch third party advisory issue tracking

Frequently Asked Questions

What is the severity of CVE-2022-29567?
CVE-2022-29567 has been scored as a medium severity vulnerability.
How to fix CVE-2022-29567?
As a workaround for remediating CVE-2022-29567: User might define either: custom `toString()` or `getId()` in their entity.
Is CVE-2022-29567 being actively exploited in the wild?
As for now, there are no information to confirm that CVE-2022-29567 is being actively exploited. According to its EPSS score, there is a ~0% probability that this vulnerability will be exploited by malicious actors in the next 30 days.
What software or system is affected by CVE-2022-29567?
CVE-2022-29567 affects Vaadin vaadin, Vaadin vaadin-grid-flow.
This platform uses data from the NIST NVD, MITRE CVE, MITRE CWE, First.org and CISA KEV but is not endorsed or certified by these entities. CVE is a registred trademark of the MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. CWE is a registred trademark of the MITRE Corporation and the authoritative source of CWE content is MITRE's CWE web site.
© 2025 Under My Watch. All Rights Reserved.