CVE-2022-29567
The default configuration of a TreeGrid component uses Object::toString as a key on the client-side and server communication in Vaadin 14.8.5 through 14.8.9, 22.0.6 through 22.0.14, 23.0.0.beta2 through 23.0.8 and 23.1.0.alpha1 through 23.1.0.alpha4, resulting in potential information disclosure of values that should not be available on the client-side.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.7
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
- EPSS probability
- 0.27%
- CWE
- CWE-200
- Published
- 2022-05-24
- Last modified
- 2026-09-14
Affected products
- Vaadin vaadin
- Vaadin vaadin
- Vaadin vaadin
- Vaadin vaadin
- Vaadin vaadin
- Vaadin vaadin-grid-flow
- Vaadin vaadin-grid-flow
- Vaadin vaadin-grid-flow
Weakness type
Related vulnerabilities
- CVE-2026-92960 — vm2 before 3.11.6 Process-wide State Exposure via os and dns
- CVE-2026-92947 — vm2 before 3.11.7 Memory Disclosure via Buffer Pool
- CVE-2026-87820 — CyberPanel 2.4.3 through 2.4.5 Information Disclosure via AI Scanner
- CVE-2026-86464 — In the current development version of Eclipse aeriOS, for which no official release has yet been published, the Identity
- CVE-2026-54617 — GravitLauncher: Unauthenticated path traversal in LaunchServer FileServerHandler
- CVE-2026-87541 — Information leak in Navigation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the
- CVE-2026-78960 — Information leak in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engin
- CVE-2026-87593 — Information leak in Editing in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive inform