CVE-2021-31403

Source
https://cve.org/CVERecord?id=CVE-2021-31403
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-31403.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2021-31403
Aliases
Published
2021-04-23T16:15:08Z
Modified
2026-07-15T10:07:35Z
Severity
  • 2.5 (Low) CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
[none]
Details

Non-constant-time comparison of CSRF tokens in UIDL request handler in com.vaadin:vaadin-server versions 7.0.0 through 7.7.23 (Vaadin 7.0.0 through 7.7.23), and 8.0.0 through 8.12.2 (Vaadin 8.0.0 through 8.12.2) allows attacker to guess a security token via timing attack

References

Affected packages

Git / github.com/vaadin/framework

Affected ranges

Type
GIT
Repo
https://github.com/vaadin/framework
Events
Database specific
Show details
{
    "cpe":  "cpe:2.3:a:vaadin:vaadin:*:*:*:*:*:*:*:*",
    "extracted_events":  [
        {
            "introduced":  "7.0.0"
        },
        {
            "fixed":  "7.7.24"
        },
        {
            "introduced":  "8.0.0"
        },
        {
            "fixed":  "8.12.3"
        }
    ],
    "source":  "CPE_RANGE"
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-31403.json"
vanir_signatures
[
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "120348944873309959167790418804657867995",
            "length":  56
        },
        "id":  "CVE-2021-31403-3792665d",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/vaadin/framework/commit/d8ba0a4d10b7f7400b524252cd5925c58ce131a4",
        "target":  {
            "file":  "client/src/main/java/com/vaadin/client/event/PointerEventSupportImplIE10.java",
            "function":  "getNativeEventName"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "11355839847430038605860934608170974081",
                "93337319848138399291306679006129482278",
                "210041750547152914784396289145157538072",
                "239308953588520565464957408716344818786",
                "130774423845043858384653373302219319406",
                "71446160060510440618345532168139805607"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2021-31403-89bf285d",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/vaadin/framework/commit/d8ba0a4d10b7f7400b524252cd5925c58ce131a4",
        "target":  {
            "file":  "client/src/main/java/com/vaadin/client/event/PointerEventSupportImplIE10.java"
        }
    }
]
vanir_signatures_modified
"2026-07-15T10:07:35Z"