Missing variable sanitization in Grid component in com.vaadin:vaadin-server versions 7.4.0 through 7.7.19 (Vaadin 7.4.0 through 7.7.19), and 8.0.0 through 8.8.4 (Vaadin 8.0.0 through 8.8.4) allows attacker to inject malicious JavaScript via unspecified vector
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| com.vaadin:vaadin-bom(Maven) | 7.4.0 | 7.7.20 | N/A |
| com.vaadin:vaadin-bom(Maven) | 8.0.0 | 8.8.5 | N/A |
| com.vaadin:vaadin-server(Maven) | 7.4.0 | 7.7.20 | N/A |
| com.vaadin:vaadin-server(Maven) | 8.0.0 | 8.8.5 | N/A |
CVSS Metrics