Description
Missing output sanitization in test sources in org.webjars.bowergithub.vaadin:vaadin-menu-bar versions 1.0.0 through 1.2.0 (Vaadin 14.0.0 through 14.4.4) allows remote attackers to execute malicious JavaScript in browser by opening crafted URL
Remediation
References
https://github.com/vaadin/vaadin-menu-bar/pull/126
https://vaadin.com/security/cve-2021-33611
Related Vulnerabilities
CVE-2021-31522 Vulnerability in maven package org.apache.kylin:kylin-server-base
CVE-2022-25167 Vulnerability in maven package org.apache.flume.flume-ng-sources:flume-jms-source
CVE-2020-13128 Vulnerability in maven package com.googlecode.gwtupload:gwtupload-project
CVE-2020-28464 Vulnerability in npm package djv
CVE-2021-23337 Vulnerability in maven package org.webjars.npm:lodash.template