Vulnerabilities
Vulnerable Software
Vaadin:  >> Vaadin  >> 7.1.8  Security Vulnerabilities
Unsafe validation RegEx in EmailValidator class in com.vaadin:vaadin-server versions 7.0.0 through 7.7.21 (Vaadin 7.0.0 through 7.7.21) allows attackers to cause uncontrolled resource consumption by submitting malicious email addresses.
CVSS Score
7.5
EPSS Score
0.007
Published
2021-04-23
Non-constant-time comparison of CSRF tokens in UIDL request handler in com.vaadin:vaadin-server versions 7.0.0 through 7.7.23 (Vaadin 7.0.0 through 7.7.23), and 8.0.0 through 8.12.2 (Vaadin 8.0.0 through 8.12.2) allows attacker to guess a security token via timing attack
CVSS Score
4.0
EPSS Score
0.001
Published
2021-04-23


Contact Us

Shodan ® - All rights reserved