{"id":"GHSA-76f4-fw33-6j2v","aliases":[],"url":"https://o3.security/vulnerability/GHSA-76f4-fw33-6j2v","summary":"Potential sensitive data exposure in applications using Vaadin 15","details":"Insecure configuration of default `ObjectMapper` in `com.vaadin:flow-server` versions 3.0.0 through 3.0.5 (Vaadin 15.0.0 through 15.0.4) may expose sensitive data if the application also uses e.g. `@RestController`\n\n- https://vaadin.com/security/cve-2020-36319","published":"2021-04-19T14:48:26Z","modified":"2024-12-02T05:26:03.528Z","cvss":{"score":3.1,"severity":"LOW","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"com.vaadin:vaadin-bom","fixedVersion":"15.0.5"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/vaadin/platform/security/advisories/GHSA-76f4-fw33-6j2v"},{"type":"PACKAGE","url":"https://github.com/vaadin/platform"},{"type":"WEB","url":"https://vaadin.com/security/cve-2020-36319"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-12-02T05:26:03.528Z"}}