CVE-2021-31408: Insufficient Session Expiration
(updated )
Authentication.logout()
helper in com.vaadin:flow-client
uses incorrect HTTP method, which, in combination with Spring Security CSRF protection, allows local attackers to access Fusion endpoints after the user attempted to log out.
References
Code Behaviors & Features
Detect and mitigate CVE-2021-31408 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →