Regular expression denial of service (ReDoS) in EmailField component in Vaadin 14 and 15-17
CVE-2021-31405

7.5HIGH

Key Information:

Vendor

Vaadin

Vendor
CVE Published:
23 April 2021

What is CVE-2021-31405?

Unsafe validation RegEx in EmailField component in com.vaadin:vaadin-text-field-flow versions 2.0.4 through 2.3.2 (Vaadin 14.0.6 through 14.4.3), and 3.0.0 through 4.0.2 (Vaadin 15.0.0 through 17.0.10) allows attackers to cause uncontrolled resource consumption by submitting malicious email addresses.

Affected Version(s)

Vaadin 14.0.6

vaadin-text-field-flow 2.0.4

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.