---
id: CVE-2023-25500
title: >-
  Possible information disclosure in Vaadin 10.0.0 to 10.0.23, 11.0.0 to
  14.10.1, 15.0.0 to 22.0.28, 23.0.0 to 23.3.13, 24.0.0 to 24.0.6, 24.1.0.alpha1
  to 24.1.0.rc2, resulting in potential information disclosure of class and
  method names …
summary: >-
  Possible information disclosure in Vaadin 10.0.0 to 10.0.23, 11.0.0 to
  14.10.1, 15.0.0 to 22.0.28, 23.0.0 to 23.3.13, 24.0.0 to 24.0.6, 24.1.0.alpha1
  to 24.1.0.rc2, resulting in potential information disclosure of class and
  method names …
severity: low
cvss: 3.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N'
cwe:
  - CWE-200
vendor: vaadin
product: vaadin
affected:
  - 'vaadin >= 10.0.0, < 10.0.23'
  - 'vaadin >= 11.0.0, < 14.10.2'
  - 'vaadin >= 15.0.0, <= 22.0.28'
  - 'vaadin >= 23.0.0, < 23.3.14'
  - 'vaadin >= 24.0.0, < 24.0.7'
  - vaadin = 24.1.0
patched:
  - vaadin 24.0.7
published: '2023-06-22'
updated: '2026-09-14'
sourceUpdated: '2026-09-14T17:17:41.473'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2023-25500'
references:
  - url: 'https://github.com/vaadin/flow/pull/16935'
    label: security@vaadin.com
  - url: 'https://vaadin.com/security/cve-2023-25500'
    label: security@vaadin.com
  - url: 'https://github.com/vaadin/flow/pull/16935'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://vaadin.com/security/cve-2023-25500'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2024-12-05T19:59:24.082540Z'
epss: 0.00514
epssPercentile: 0.41312
ingestedAt: '2026-09-14T18:12:17.151Z'
---

## Overview

Possible information disclosure in Vaadin 10.0.0 to 10.0.23, 11.0.0 to 14.10.1, 15.0.0 to 22.0.28, 23.0.0 to 23.3.13, 24.0.0 to 24.0.6, 24.1.0.alpha1 to 24.1.0.rc2, resulting in potential information disclosure of class and method names in RPC responses by sending modified requests.

## Affected

- `vaadin >= 10.0.0, < 10.0.23`
- `vaadin >= 11.0.0, < 14.10.2`
- `vaadin >= 15.0.0, <= 22.0.28`
- `vaadin >= 23.0.0, < 23.3.14`
- `vaadin >= 24.0.0, < 24.0.7`
- `vaadin = 24.1.0`

## Remediation

Upgrade past the affected range:

- `vaadin 24.0.7`
