Description
Improper URL validation in development mode handler in com.vaadin:flow-server versions 2.0.0 through 2.4.1 (Vaadin 14.0.0 through 14.4.2), and 3.0 prior to 5.0 (Vaadin 15 prior to 18) allows attacker to request arbitrary files stored outside of intended frontend resources folder.
Remediation
References
https://github.com/vaadin/flow/pull/9392
https://vaadin.com/security/cve-2020-36321
Related Vulnerabilities
CVE-2011-1772 Vulnerability in maven package org.apache.struts.xwork:xwork-core
CVE-2022-22968 Vulnerability in maven package org.springframework:spring-context
CVE-2022-3423 Vulnerability in npm package nocodb
CVE-2021-24033 Vulnerability in npm package react-dev-utils
CVE-2022-23496 Vulnerability in maven package nl.basjes.parse.useragent:yauaa