CVE-2023-25499

Executive Summary

In Vaadin versions 10.0.0–10.0.22, 11.0.0–14.10.0, 15.0.0–22.0.28, 23.0.0–23.3.12, 24.0.0–24.0.5, and 24.1.0.alpha1–beta1, content from non‑visible UI components is inadvertently sent to the browser during server‑side rendering. This flaw can expose sensitive data to end users, constituting an information‑disclosure vulnerability. The issue is not yet listed in the CISA KEV database.


Authoritative CVE Metadata - CVSS Base Score: 5.7 (MEDIUM) - Published: 2023-06-22T13:15:09.660 - Last Modified: 2026-09-14T16:17:04.217

Original Description: When adding non-visible components to the UI in server side, content is sent to the browser in Vaadin 10.0.0 through 10.0.22, 11.0.0 through 14.10.0, 15.0.0 through 22.0.28, 23.0.0 through 23.3.12, 24.0.0 through 24.0.5 and 24.1.0.alpha1 to 24.1.0.beta1, resulting in potential information disclosure.

"Limitations live only in our minds. But if we use our imaginations, our possibilities become limitless."

— Jamie Paolinetti
Source: NVD