Vulnerabilities
Vulnerable Software
Vaadin:  >> Flow  >> 5.0.4  Security Vulnerabilities
Authentication.logout() helper in com.vaadin:flow-client versions 5.0.0 prior to 6.0.0 (Vaadin 18), and 6.0.0 through 6.0.4 (Vaadin 19.0.0 through 19.0.3) uses incorrect HTTP method, which, in combination with Spring Security CSRF protection, allows local attackers to access Fusion endpoints after the user attempted to log out.
CVSS Score
6.3
EPSS Score
0.001
Published
2021-04-23


Contact Us

Shodan ® - All rights reserved