The deep merge helpers in Vaadin Charts and in the i18n support of Vaadin components copy properties without filtering keys that address the prototype chain, so merging data the application does not control can add properties to Object.prototype and make them visible to every object in the running application.
See CWE-1321: Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
Description
Both @vaadin/charts and the I18nMixin in @vaadin/component-base carry a recursive merge helper that copies properties from a caller supplied object into a target object without filtering keys that address the prototype chain. A __proto__ key whose value is an object therefore writes onto Object.prototype, and because every ordinary JavaScript object inherits from it, the injected properties become visible throughout the application. This can corrupt application logic, cause a denial of service, or act as a gadget for further attacks.
The vulnerability is reached where an application assigns an object it did not construct itself, typically one parsed from JSON, to the i18n property of a component, to the additionalOptions property of <vaadin-chart> or <vaadin-chart-series>, or to updateConfiguration() of <vaadin-chart>. No special configuration is required.
Applications using the Java (Flow) API are not affected through the setI18n() APIs or the chart Configuration model, because the property names sent to the client originate from typed Java models. The one exception is Exporting.setMenuItemDefinitions(), whose map keys are supplied by the application.
The i18n merge was introduced in Vaadin 24.7.0, so versions before that are affected through Vaadin Charts only.
Affected products and mitigation
Users of affected versions should apply the following mitigation or upgrade. Releases that have fixed this issue include:
| Product version |
Mitigation |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Upgrade to 25.2.7 or newer
|
Please note that Vaadin versions 10-13 and 15-22 are no longer supported and you should update either to the latest 23, 24, 25 version.
Artifacts
| Maven coordinates |
Vulnerable version |
Fixed version |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
com.vaadin:vaadin-charts-flow
|
|
|
com.vaadin:vaadin-charts-flow
|
|
|
com.vaadin:vaadin-charts-flow
|
|
|
com.vaadin:vaadin-charts-flow
|
|
|
com.vaadin:vaadin-charts-flow
|
|
|
com.vaadin:vaadin-core is affected from 24.7.0 onwards only: Vaadin Charts is not part of Vaadin core, so an application using core alone is exposed through the i18n merge, which was introduced in 24.7.0.
| npm package |
Vulnerable version |
Fixed version |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
The npm versions are the web components versions and do not match the Vaadin product versions.
References
https://github.com/vaadin/web-components/pull/12483
Credit
Reported by Ridwan Arefin Islam - Madiba Security Lab, Concordia University.