CVE-2022-29567
Possible information disclosure inside TreeGrid component with default data provider
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The default configuration of a TreeGrid component uses Object::toString as a key on the client-side and server communication in Vaadin 14.8.5 through 14.8.9, 22.0.6 through 22.0.14, 23.0.0.beta2 through 23.0.8 and 23.1.0.alpha1 through 23.1.0.alpha4, resulting in potential information disclosure of values that should not be available on the client-side.
La configuración por defecto de un componente TreeGrid usa Object::toString como clave en la comunicación con el cliente y el servidor en Vaadin versiones 14.8.5 hasta 14.8.9, 22.0.6 hasta 22.0.14, 23.0.0.beta2 hasta 23.0.8 y 23.1.0.alpha1 hasta 23.1.0.alpha4, resultando en una potencial divulgación de información de valores que no deberían estar disponibles en el lado del cliente
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-04-21 CVE Reserved
- 2022-05-24 CVE Published
- 2023-12-15 EPSS Updated
- 2024-09-16 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/vaadin/flow-components/pull/3046 | 2022-06-07 |
URL | Date | SRC |
---|---|---|
https://vaadin.com/security/cve-2022-29567 | 2022-06-07 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Vaadin Search vendor "Vaadin" | Vaadin Search vendor "Vaadin" for product "Vaadin" | >= 14.8.5 <= 14.8.9 Search vendor "Vaadin" for product "Vaadin" and version " >= 14.8.5 <= 14.8.9" | - |
Affected
| ||||||
Vaadin Search vendor "Vaadin" | Vaadin Search vendor "Vaadin" for product "Vaadin" | >= 22.0.6 <= 22.0.15 Search vendor "Vaadin" for product "Vaadin" and version " >= 22.0.6 <= 22.0.15" | - |
Affected
| ||||||
Vaadin Search vendor "Vaadin" | Vaadin Search vendor "Vaadin" for product "Vaadin" | >= 23.0.1 <= 23.0.8 Search vendor "Vaadin" for product "Vaadin" and version " >= 23.0.1 <= 23.0.8" | - |
Affected
| ||||||
Vaadin Search vendor "Vaadin" | Vaadin Search vendor "Vaadin" for product "Vaadin" | 23.0.0 Search vendor "Vaadin" for product "Vaadin" and version "23.0.0" | - |
Affected
| ||||||
Vaadin Search vendor "Vaadin" | Vaadin Search vendor "Vaadin" for product "Vaadin" | 23.0.0 Search vendor "Vaadin" for product "Vaadin" and version "23.0.0" | beta2 |
Affected
| ||||||
Vaadin Search vendor "Vaadin" | Vaadin Search vendor "Vaadin" for product "Vaadin" | 23.0.0 Search vendor "Vaadin" for product "Vaadin" and version "23.0.0" | beta3 |
Affected
| ||||||
Vaadin Search vendor "Vaadin" | Vaadin Search vendor "Vaadin" for product "Vaadin" | 23.0.0 Search vendor "Vaadin" for product "Vaadin" and version "23.0.0" | beta4 |
Affected
| ||||||
Vaadin Search vendor "Vaadin" | Vaadin Search vendor "Vaadin" for product "Vaadin" | 23.0.0 Search vendor "Vaadin" for product "Vaadin" and version "23.0.0" | rc1 |
Affected
| ||||||
Vaadin Search vendor "Vaadin" | Vaadin Search vendor "Vaadin" for product "Vaadin" | 23.1.0 Search vendor "Vaadin" for product "Vaadin" and version "23.1.0" | alpha1 |
Affected
| ||||||
Vaadin Search vendor "Vaadin" | Vaadin Search vendor "Vaadin" for product "Vaadin" | 23.1.0 Search vendor "Vaadin" for product "Vaadin" and version "23.1.0" | alpha2 |
Affected
| ||||||
Vaadin Search vendor "Vaadin" | Vaadin Search vendor "Vaadin" for product "Vaadin" | 23.1.0 Search vendor "Vaadin" for product "Vaadin" and version "23.1.0" | alpha3 |
Affected
| ||||||
Vaadin Search vendor "Vaadin" | Vaadin Search vendor "Vaadin" for product "Vaadin" | 23.1.0 Search vendor "Vaadin" for product "Vaadin" and version "23.1.0" | alpha4 |
Affected
|