Denial of service in DataCommunicator class in Vaadin 8
Package
Affected versions
>= 8.0.6, < 8.14.1
Patched versions
8.14.1
Description
Published by the National Vulnerability Database
Oct 13, 2021
Reviewed
Oct 13, 2021
Published to the GitHub Advisory Database
Oct 13, 2021
Last updated
May 15, 2024
Missing check in
DataCommunicator
class incom.vaadin:vaadin-server
versions 8.0.0 through 8.14.0 (Vaadin 8.0.0 through 8.14.0) allows authenticated network attacker to cause heap exhaustion by requesting too many rows of data.References