Denial of service in DataCommunicator class in Vaadin 8
Package
Affected versions
>= 8.0.0, < 8.14.1
Patched versions
8.14.1
Description
Reviewed
Oct 13, 2021
Published to the GitHub Advisory Database
Oct 13, 2021
Last updated
Jan 9, 2023
Missing check in
DataCommunicator
class incom.vaadin:vaadin-server
versions 8.0.0 through 8.14.0 (Vaadin 8.0.0 through 8.14.0) allows authenticated network attacker to cause heap exhaustion by requesting too many rows of data.References