CVE-2021-33604 is a URL encoding error affecting Vaadin Flow Server versions 2.0.0 through 2.6.1 (Vaadin 14.0.0-14.6.1) and 3.0.0 through 6.0.9 (Vaadin 15.0.0-19.0.8). This vulnerability allows a local user to execute arbitrary JavaScript by opening a specially crafted URL in their browser. It is rated with a low CVSS score of 2.5, indicating a low attack complexity and requiring user interaction, with a limited impact on confidentiality. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.0.0, <= 2.6.1CPE matchmatch criteria | cpe:2.3:a:vaadin:flow-server:*:*:*:*:*:*:*:* | ||
>= 3.0.0, <= 5.0.0CPE matchmatch criteria | cpe:2.3:a:vaadin:flow-server:*:*:*:*:*:*:*:* | ||
>= 6.0.0, <= 6.0.9CPE matchmatch criteria | cpe:2.3:a:vaadin:flow-server:*:*:*:*:*:*:*:* | ||
>= 14.0.0, <= 14.6.1CPE matchmatch criteria | cpe:2.3:a:vaadin:vaadin:*:*:*:*:*:*:*:* | ||
>= 15.0.0, <= 18.0.0CPE matchmatch criteria | cpe:2.3:a:vaadin:vaadin:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.