CVE-2023-25499
Vaadin vulnerable to possible information disclosure in non visible components.
5.7
MEDIUM
CVSS 3.1
EPSS 0.58%
描述
### Description When adding non-visible components to the UI in server side, content is sent to the browser in Vaadin 10.0.0 through 10.0.22, 11.0.0 through 14.10.0, 15.0.0 through 22.0.28, 23.0.0 through 23.3.12, 24.0.0 through 24.0.5 and 24.1.0.alpha1 to 24.1.0.beta1, resulting in potential information disclosure. * https://vaadin.com/security/cve-2023-25499
如何修補 CVE-2023-25499
要修補 CVE-2023-25499,請將受影響套件升級到下列已修補版本。
- —升級至 1.0.20 或更新版本
- —升級至 10.0.23 或更新版本
CVE-2023-25499 正在被利用嗎?
低 — EPSS 為 0.6%,目前沒有觀察到大規模利用活動。
受影響套件(2)
- >= 1.0.0, < 1.0.20
- >= 10.0.0, < 10.0.23
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.7 | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N |