CVE-2023-25500
Executive Summary
CVE-2023-25500 exposes class and method names in Vaadin RPC responses for versions 10.0.0‑10.0.23, 11.0.0‑14.10.1, 15.0.0‑22.0.28, 23.0.0‑23.3.13, 24.0.0‑24.0.6, 24.1.0.alpha1‑24.1.0.rc2. Attackers can craft modified requests to trigger the disclosure. No KEV listing yet.
Authoritative CVE Metadata - CVSS Base Score: 3.5 (LOW) - Published: 2023-06-22T13:15:09.737 - Last Modified: 2026-09-14T17:17:41.473
Original Description: Possible information disclosure in Vaadin 10.0.0 to 10.0.23, 11.0.0 to 14.10.1, 15.0.0 to 22.0.28, 23.0.0 to 23.3.13, 24.0.0 to 24.0.6, 24.1.0.alpha1 to 24.1.0.rc2, resulting in potential information disclosure of class and method names in RPC responses by sending modified requests.
"He that is giddy thinks the world turns round."
— William Shakespeare