#VU81287 Observable discrepancy in framework - CVE-2021-31403
Published: September 29, 2023
framework
vaadin
Description
The vulnerability allows a local user to gain access to potentially sensitive information.
The vulnerability exists due to non-constant-time comparison of CSRF tokens in UIDL request handler. A local user can guess a security token for Fusion endpoints and then use this information to launch further attacks against the affected system.