Description
Possible information disclosure in Vaadin 10.0.0 to 10.0.23, 11.0.0 to 14.10.1, 15.0.0 to 22.0.28, 23.0.0 to 23.3.13, 24.0.0 to 24.0.6, 24.1.0.alpha1 to 24.1.0.rc2, resulting in potential information disclosure of class and method names in RPC responses by sending modified requests.
Remediation
References
https://github.com/vaadin/flow/pull/16935
https://vaadin.com/security/cve-2023-25500
Related Vulnerabilities
CVE-2022-22912 Vulnerability in npm package plist
CVE-2020-15149 Vulnerability in npm package nodebb
CVE-2019-10759 Vulnerability in maven package org.webjars.npm:safer-eval
CVE-2016-3506 Vulnerability in maven package com.oracle:ojdbc7
CVE-2021-41084 Vulnerability in maven package org.http4s:http4s-server_3