CVE-2022-29567
Possible information disclosure inside TreeGrid component with default data provider
5.7
MEDIUM
CVSS 3.1
EPSS 0.92%
描述
### Description The default configuration of a TreeGrid component uses Object::toString as a key on the client-side and server communication in Vaadin 14.8.5 through 14.8.9, 22.0.6 through 22.0.14, 23.0.0.beta2 through 23.0.8 and 23.1.0.alpha1 through 23.1.0.alpha4, resulting in potential information disclosure of values that should not be available on the client-side.
如何修補 CVE-2022-29567
要修補 CVE-2022-29567,請將受影響套件升級到下列已修補版本。
- —升級至 14.8.10 或更新版本
- —升級至 14.8.10 或更新版本
CVE-2022-29567 正在被利用嗎?
低 — EPSS 為 0.9%,目前沒有觀察到大規模利用活動。
受影響套件(2)
- >= 14.8.5, < 14.8.10
- >= 14.8.5, < 14.8.10
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.7 | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N |