CVE-2022-29567 is a vulnerability in Vaadin
Published on May 24, 2022
Possible information disclosure inside TreeGrid component with default data provider
The default configuration of a TreeGrid component uses Object::toString as a key on the client-side and server communication in Vaadin 14.8.5 through 14.8.9, 22.0.6 through 22.0.14, 23.0.0.beta2 through 23.0.8 and 23.1.0.alpha1 through 23.1.0.alpha4, resulting in potential information disclosure of values that should not be available on the client-side.
Vulnerability Analysis
CVE-2022-29567 can be exploited with network access, requires user interaction and a small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality, with no impact on integrity and availability.
Weakness Type
What is an Information Disclosure Vulnerability?
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVE-2022-29567 has been classified to as an Information Disclosure vulnerability or weakness.
Products Associated with CVE-2022-29567
Want to know whenever a new CVE is published for Vaadin? stack.watch will email you.
Affected Versions
vaadin:- Version 14.8.5 and below unspecified is affected.
- Version unspecified, <= 14.8.9 is affected.
- Version 22.0.6 and below unspecified is affected.
- Version unspecified, <= 22.0.14 is affected.
- Version 23.0.0.beta2 and below unspecified is affected.
- Version unspecified, <= 23.0.8 is affected.
- Version 23.1.0.alpha1 and below unspecified is affected.
- Version unspecified, <= 23.1.0.alpha4 is affected.
- Version 14.8.5 and below unspecified is affected.
- Version unspecified, <= 14.8.9 is affected.
- Version 22.0.6 and below unspecified is affected.
- Version unspecified, <= 22.0.14 is affected.
- Version 23.0.0.beta2 and below unspecified is affected.
- Version unspecified, <= 23.0.8 is affected.
- Version 23.1.0.alpha1 and below unspecified is affected.
- Version unspecified, <= 23.1.0.alpha4 is affected.
Vulnerable Packages
The following package name and versions may be associated with CVE-2022-29567
| Package Manager | Vulnerable Package | Versions | Fixed In |
|---|---|---|---|
| maven | com.vaadin:vaadin | >= 14.8.5, < 14.8.10 | 14.8.10 |
| maven | com.vaadin:vaadin | >= 22.0.6, < 22.0.15 | 22.0.15 |
| maven | com.vaadin:vaadin | >= 23.0.0, < 23.0.9 | 23.0.9 |
| maven | com.vaadin:vaadin-grid-flow | >= 14.8.5, < 14.8.10 | 14.8.10 |
| maven | com.vaadin:vaadin-grid-flow | >= 22.0.6, < 22.0.15 | 22.0.15 |
| maven | com.vaadin:vaadin-grid-flow | >= 23.0.0, < 23.0.9 | 23.0.9 |
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.