Unsafe validation RegEx in EmailField component in com.vaadin:vaadin-text-field-flow versions 2.0.4 through 2.3.2 (Vaadin 14.0.6 through 14.4.3), and 3.0.0 through 4.0.2 (Vaadin 15.0.0 through 17.0.10) allows attackers to cause uncontrolled resource consumption by submitting malicious email addresses.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-31405.json"
[
{
"source": "https://github.com/vaadin/flow/commit/555d8ec6a948409588da228130ef5acace25e21b",
"digest": {
"line_hashes": [
"250998033722216792632573282675630447206",
"51357056711319790771051396733484605111",
"237030694747446891984013541902574182491",
"339189658215978485053921588396936469055"
],
"threshold": 0.9
},
"id": "CVE-2021-31405-be73239d",
"deprecated": false,
"signature_type": "Line",
"signature_version": "v1",
"target": {
"file": "flow-data/src/main/java/com/vaadin/flow/data/provider/DataCommunicator.java"
}
}
]