CVE-2021-31412
Estado: ModificadaMedia (5.3)—
Improper sanitization of path in default RouteNotFoundError view in com.vaadin:flow-server versions 1.0.0 through 1.0.14 (Vaadin 10.0.0 through 10.0.18), 1.1.0 prior to 2.0.0 (Vaadin 11 prior to 14), 2.0.0 through 2.6.1 (Vaadin 14.0.0 through 14.6.1), and 3.0.0 through 6.0.9 (Vaadin 15.0.0 through 19.0.8) allows network attacker to enumerate all available routes via crafted HTTP request when application is running in production mode and no custom handler for NotFoundException is provided.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Puntuación base: 5.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.32%
- Percentil entre todas las CVEs puntuadas: 70
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- CWE-1295
- CWE-20
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2021-31412",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "MEDIUM",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security@vaadin.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 1.4,
"exploitabilityScore": 3.9
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 1.4,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "security@vaadin.com",
"affectedData": [
{
"vendor": "Vaadin",
"product": "Vaadin",
"versions": [
{
"status": "affected",
"version": "10.0.0",
"lessThan": "unspecified",
"versionType": "custom"
},
{
"status": "affected",
"version": "unspecified",
"versionType": "custom",
"lessThanOrEqual": "10.0.18"
},
{
"status": "affected",
"version": "11.0.0",
"lessThan": "unspecified",
"versionType": "custom"
},
{
"status": "affected",
"version": "unspecified",
"lessThan": "14.0.0",
"versionType": "custom"
},
{
"status": "affected",
"version": "14.0.0",
"lessThan": "unspecified",
"versionType": "custom"
},
{
"status": "affected",
"version": "unspecified",
"versionType": "custom",
"lessThanOrEqual": "14.6.1"
},
{
"status": "affected",
"version": "15.0.0",
"lessThan": "unspecified",
"versionType": "custom"
},
{
"status": "affected",
"version": "unspecified",
"versionType": "custom",
"lessThanOrEqual": "19.0.8"
}
]
},
{
"vendor": "Vaadin",
"product": "flow-server",
"versions": [
{
"status": "affected",
"version": "1.0.0",
"lessThan": "unspecified",
"versionType": "custom"
},
{
"status": "affected",
"version": "unspecified",
"versionType": "custom",
"lessThanOrEqual": "1.0.14"
},
{
"status": "affected",
"version": "1.1.0",
"lessThan": "unspecified",
"versionType": "custom"
},
{
"status": "affected",
"version": "unspecified",
"lessThan": "2.0.0",
"versionType": "custom"
},
{
"status": "affected",
"version": "2.0.0",
"lessThan": "unspecified",
"versionType": "custom"
},
{
"status": "affected",
"version": "unspecified",
"versionType": "custom",
"lessThanOrEqual": "2.6.1"
},
{
"status": "affected",
"version": "3.0.0",
"lessThan": "unspecified",
"versionType": "custom"
},
{
"status": "affected",
"version": "unspecified",
"versionType": "custom",
"lessThanOrEqual": "6.0.9"
}
]
}
]
}
],
"published": "2021-06-24T12:15:08.090",
"references": [
{
"url": "https://github.com/vaadin/flow/pull/11107",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "security@vaadin.com"
},
{
"url": "https://vaadin.com/security/cve-2021-31412",
"tags": [
"Vendor Advisory"
],
"source": "security@vaadin.com"
},
{
"url": "https://github.com/vaadin/flow/pull/11107",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://vaadin.com/security/cve-2021-31412",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "security@vaadin.com",
"description": [
{
"lang": "en",
"value": "CWE-1295"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Improper sanitization of path in default RouteNotFoundError view in com.vaadin:flow-server versions 1.0.0 through 1.0.14 (Vaadin 10.0.0 through 10.0.18), 1.1.0 prior to 2.0.0 (Vaadin 11 prior to 14), 2.0.0 through 2.6.1 (Vaadin 14.0.0 through 14.6.1), and 3.0.0 through 6.0.9 (Vaadin 15.0.0 through 19.0.8) allows network attacker to enumerate all available routes via crafted HTTP request when application is running in production mode and no custom handler for NotFoundException is provided."
},
{
"lang": "es",
"value": "Un saneamiento inapropiado de la ruta en la vista RouteNotFoundError predeterminada en com.vaadin:flow-server versiones 1.0.0 hasta 1.0.14 (Vaadin versiones 10.0.0 hasta 10.0.18), versiones 1.1.0 anteriores a 2.0.0 (Vaadin versiones 11 anterior a 14), versiones 2.0.0 hasta 2.6.1 (Vaadin versiones 14.0.0 hasta 14. 6.1), y versiones 3.0.0 hasta 6.0.9 (Vaadin versiones 15.0.0 hasta 19.0.8) permite a un atacante de red enumerar todas las rutas disponibles por medio de una petición HTTP diseñada cuando la aplicación se ejecuta en modo de producción y un controlador personalizado para o NotFoundException es proporcionado"
}
],
"lastModified": "2026-06-17T03:51:44.080",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:vaadin:flow:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "08B5A131-071A-4AEC-9F0B-8BF6D38DC85C",
"versionEndIncluding": "1.0.14",
"versionStartIncluding": "1.0.0"
},
{
"criteria": "cpe:2.3:a:vaadin:flow:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4F232EDE-AF65-4AA2-846E-3C7A34DA8928",
"versionEndIncluding": "1.4.0",
"versionStartIncluding": "1.1.0"
},
{
"criteria": "cpe:2.3:a:vaadin:flow:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DAF9CA63-A40E-474E-9BE9-8A86A1C2B129",
"versionEndIncluding": "2.6.1",
"versionStartIncluding": "2.0.0"
},
{
"criteria": "cpe:2.3:a:vaadin:flow:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2CA90E82-620F-46C0-AB1F-05804328BB54",
"versionEndIncluding": "5.0.0",
"versionStartIncluding": "3.0.0"
},
{
"criteria": "cpe:2.3:a:vaadin:flow:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1551D996-DB49-4E39-9423-BD3CBA2029FA",
"versionEndIncluding": "6.0.9",
"versionStartIncluding": "6.0.0"
},
{
"criteria": "cpe:2.3:a:vaadin:vaadin:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6AAF5648-26F2-4D08-838B-3B3C2E0954D2",
"versionEndIncluding": "10.0.18",
"versionStartIncluding": "10.0.0"
},
{
"criteria": "cpe:2.3:a:vaadin:vaadin:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "85960C27-DA5B-4215-9C34-4789F32EF260",
"versionEndIncluding": "13.0.0",
"versionStartIncluding": "11.0.0"
},
{
"criteria": "cpe:2.3:a:vaadin:vaadin:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4367271F-BC87-4C32-BBFC-F9F97ACD2D33",
"versionEndIncluding": "14.6.1",
"versionStartIncluding": "14.0.0"
},
{
"criteria": "cpe:2.3:a:vaadin:vaadin:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DC99FEC9-DABA-4E7E-AA04-67146840B360",
"versionEndIncluding": "18.0.0",
"versionStartIncluding": "15.0.0"
},
{
"criteria": "cpe:2.3:a:vaadin:vaadin:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "64FCA0F3-0104-490C-B8CA-860B52BCAC29",
"versionEndIncluding": "19.0.8",
"versionStartIncluding": "19.0.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security@vaadin.com"
}