CVE-2023-25500: Vaadin
Medium severity, CVSS 4.3. EPSS: 0.5% chance of exploitation in the next 30 days.
Possible information disclosure in Vaadin 10.0.0 to 10.0.23, 11.0.0 to 14.10.1, 15.0.0 to 22.0.28, 23.0.0 to 23.3.13, 24.0.0 to 24.0.6, 24.1.0.alpha1 to 24.1.0.rc2, resulting in potential information disclosure of class and method names in RPC responses by sending modified requests.
Affected products
- Vaadin Vaadin: from 10.0.0, before 10.0.23 (fixed in 10.0.23); from 11.0.0, before 14.10.2 (fixed in 14.10.2); from 15.0.0, up to and including 22.0.28; from 23.0.0, before 23.3.14 (fixed in 23.3.14); from 24.0.0, before 24.0.7 (fixed in 24.0.7); version 24.1.0 only
Published 2023-06-22. Last modified 2026-09-14.