CVE-2021-31411

Source
https://cve.org/CVERecord?id=CVE-2021-31411
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-31411.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2021-31411
Aliases
Published
2021-05-05T19:15:08Z
Modified
2026-08-07T16:50:19Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Insecure temporary directory usage in frontend build functionality of com.vaadin:flow-server versions 2.0.9 through 2.5.2 (Vaadin 14.0.3 through Vaadin 14.5.2), 3.0 prior to 6.0 (Vaadin 15 prior to 19), and 6.0.0 through 6.0.5 (Vaadin 19.0.0 through 19.0.4) allows local users to inject malicious code into frontend resources during application rebuilds.

References

Affected packages

Git / github.com/vaadin/flow

Affected ranges

Type
GIT
Repo
https://github.com/vaadin/flow
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:vaadin:flow:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "2.0.9"
        },
        {
            "fixed": "2.5.3"
        },
        {
            "introduced": "3.0.0"
        },
        {
            "last_affected": "5.0.0"
        },
        {
            "introduced": "6.0.0"
        },
        {
            "last_affected": "6.0.6"
        }
    ],
    "source": "CPE_RANGE"
}

Affected versions

6.*
6.0.0
6.0.0.rc1
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-31411.json"
vanir_signatures
[
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "274118860405830707737187343030887766150",
                "327559721548196134147450388879998528952",
                "231391270674709341178973814261592708464",
                "211979396369304634247134746982955007251",
                "32900508480395475606250217170485575868",
                "80791419901938608036810617882838820733",
                "6026733202762934250207559657693826010",
                "17187701696772157707955369838765636321",
                "14585976683169020273786467247984779635",
                "136419670407895535633809878805326991124",
                "60136359027831226858976120404744046768",
                "171023654744543184735012727835208935228",
                "48270102157939833231118982497687312218",
                "175188813783905405808930999300082626303",
                "220604571186367106147995826939082644094",
                "15956785489358244696973139203321284713",
                "133908307871722389377786052986188030614",
                "172201478849480036233153468210094773069",
                "16731467310513679515719110523690099220",
                "325339830852643423504391538910603562036",
                "220115242206324016293745746735881530016",
                "139147795175099503122261681307185114248",
                "126281408131594152747505327874700784215"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2021-31411-5f3d7805",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/vaadin/flow/commit/995027d29ee538e7f707b2454686be75f02977ef",
        "target": {
            "file": "flow-server/src/main/java/com/vaadin/flow/server/frontend/JarContentsManager.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "241441924087109472839976369467669757191",
            "length": 802
        },
        "id": "CVE-2021-31411-e6b195bb",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/vaadin/flow/commit/995027d29ee538e7f707b2454686be75f02977ef",
        "target": {
            "file": "flow-server/src/main/java/com/vaadin/flow/server/frontend/JarContentsManager.java",
            "function": "copyJarEntryTrimmingBasePath"
        }
    }
]
vanir_signatures_modified
"2026-08-07T16:50:19Z"

Git / github.com/vaadin/platform

Affected ranges

Type
GIT
Repo
https://github.com/vaadin/platform
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:vaadin:vaadin:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "14.0.3"
        },
        {
            "fixed": "14.5.3"
        },
        {
            "introduced": "15.0.0"
        },
        {
            "fixed": "19.0.5"
        }
    ],
    "source": "CPE_RANGE"
}

Affected versions

15.*
15.0.0
15.0.0.rc1
16.*
16.0.0.alpha1
16.0.0.alpha2
16.0.0.alpha3
16.0.1
17.*
17.0.0
17.0.0.alpha2
17.0.0.alpha3
17.0.0.alpha4
17.0.0.alpha5
17.0.0.alpha6
17.0.0.alpha7
17.0.0.beta1
17.0.0.beta2
17.0.0.beta3
17.0.0.rc1
17.0.0.rc2
18.*
18.0.0.alpha1
18.0.0.beta1
18.0.0.beta2
19.*
19.0.0
19.0.0.alpha1
19.0.0.alpha2
19.0.0.alpha3
19.0.0.alpha4
19.0.0.alpha5
19.0.0.beta1
19.0.0.beta2
19.0.0.beta3
19.0.0.rc1
19.0.1
19.0.2
19.0.3
19.0.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-31411.json"

Git / github.com/vaadin/vaadin

Affected ranges

Type
GIT
Repo
https://github.com/vaadin/vaadin
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:vaadin:vaadin:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "14.0.3"
        },
        {
            "fixed": "14.5.3"
        },
        {
            "introduced": "15.0.0"
        },
        {
            "fixed": "19.0.5"
        }
    ],
    "source": "CPE_RANGE"
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-31411.json"