Release date: 2013-02-01
Updated on:
Affected Systems:
Vaadin 6.x
Vaadin
Description:
--------------------------------------------------------------------------------
Vaadin is a Java application development framework and can be used under the Apache 2 certificate.
Com. Vaadin. terminal. gwt. server. JsonPaintTarget. addAttribute (String, Map <?, ?>) The method does not properly escape the "Map" parameter key, which can cause arbitrary HTML and script code to be inserted. After the malicious data is viewed, it is executed in the user's browser session.
<* Source: vendor
Link: http://secunia.com/advisories/52063/
Https://vaadin.com/forum/-/message_boards/view_message/2456529
Http://dev.vaadin.com/ticket/10873
Http://dev.vaadin.com/ticket/10873
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Vaadin
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://vaadin.com/download/release/6.8/6.8.8/release-notes.html#security-fixes