PT-2026-103275 · Vaadin · Vaadin
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Vaadin versions 23.1.0 through 23.6.13
Vaadin versions 24.0.0 through 24.9.21
Vaadin versions 24.10.0 through 24.10.9
Vaadin versions 25.0.0 through 25.1.11
Vaadin versions 25.2.0 through 25.2.6
Vaadin Framework 7 and 8 with Spreadsheet add-on versions 2.0.0 through 3.1.0
Description
A missing authorization check in the Vaadin Spreadsheet component allows an authenticated user to add or replace cell comments on a sheet with protection enabled, including locked cells. Additionally, writing a comment to a non-existent cell will result in the creation of both the row and the cell.
Recommendations
Upgrade Vaadin versions 23.1.0 through 23.6.13 to 23.6.14.
Upgrade Vaadin versions 24.0.0 through 24.9.21 to 24.9.22.
Upgrade Vaadin versions 24.10.0 through 24.10.9 to 24.10.10.
Upgrade Vaadin versions 25.0.0 through 25.1.11 to 25.1.12.
Upgrade Vaadin versions 25.2.0 through 25.2.6 to 25.2.7 or newer.
Upgrade the Spreadsheet add-on for Vaadin Framework 7 and 8 to 3.1.1.
Fix
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vaadin