Information Disclosure Vulnerability in Vaadin Products by Vaadin
CVE-2023-25500
3.5LOW
What is CVE-2023-25500?
This vulnerability in the Vaadin Framework can lead to unintentional exposure of sensitive class and method names via manipulated RPC requests. When specific requests are altered, it enables the potential leakage of internal application details that can be exploited by malicious actors. Applications using affected versions should implement security measures to mitigate unauthorized information exposure.
Affected Version(s)
flow-server 1.0.0 <= 1.0.20
flow-server 1.1.0 <= 2.9.2
flow-server 3.0.0 <= 9.1.1
