Vaadin Build Plugins is Affected by a Possible Information Disclosure Vulnerability

Description

A possible information disclosure vulnerability exists in the Vaadin Maven plugin and Vaadin Gradle plugin that exposes the full set of environment variables in build logs whenever the frontend build process exits with a non-zero status. Because the build environment may contain credentials supplied as secrets, any failed frontend build can expose those secrets in clear text in CI logs and archived build artifacts.

Users of affected versions should apply the following mitigation or upgrade. Releases that have fixed this issue include:

Product version Mitigation
Vaadin 23.0.0 - 23.6.10 Upgrade to 23.6.11
Vaadin 24.0.0 - 24.9.17 Upgrade to 24.9.18
Vaadin 24.10.0 - 24.10.3 Upgrade to 24.10.4
Vaadin 25.0.0 - 25.0.11 Upgrade to 25.0.12
Vaadin 25.1.0 - 25.1.4 Upgrade to 25.1.5 or newer

Please note that Vaadin versions 10-13 and 15-22 are no longer supported and you should update either to the latest 23, 24, or 25 version.

Maven coordinates Vulnerable version Fixed version
com.vaadin:flow-plugin-base 23.0.0 - 23.6.10 ≥ 23.6.11
com.vaadin:flow-plugin-base 24.0.0 - 24.9.17 ≥ 24.9.18
com.vaadin:flow-plugin-base 24.0.0 - 24.10.3 ≥ 24.10.4
com.vaadin:flow-plugin-base 25.0.0 - 25.0.11 ≥ 25.0.12
com.vaadin:flow-plugin-base 25.1.0 - 25.1.4 ≥ 25.1.5
com.vaadin:flow-maven-plugin 23.0.0 - 23.6.10 ≥ 23.6.11
com.vaadin:flow-maven-plugin 24.0.0 - 24.9.17 ≥ 24.9.18
com.vaadin:flow-maven-plugin 24.0.0 - 24.10.3 ≥ 24.10.4
com.vaadin:flow-maven-plugin 25.0.0 - 25.0.11 ≥ 25.0.12
com.vaadin:flow-maven-plugin 25.1.0 - 25.1.4 ≥ 25.1.5
com.vaadin:flow-gradle-plugin 24.0.0 - 24.9.17 ≥ 24.9.18
com.vaadin:flow-gradle-plugin 24.0.0 - 24.10.3 ≥ 24.10.4
com.vaadin:flow-gradle-plugin 25.0.0 - 25.0.11 ≥ 25.0.12
com.vaadin:flow-gradle-plugin 25.1.0 - 25.1.4 ≥ 25.1.5

Basic information

Type
reviewed
Severity
low
Advisory on GitHub
Open advisory ↗
Repository advisory
Source code
Browse source ↗
Published (advisory)
2026-05-19 12:31:42 UTC
Updated
2026-06-04 18:38:35 UTC
GitHub reviewed
2026-06-04 18:38:34 UTC
NVD published
2026-05-19

EPSS Score

Score Percentile
0.02% 3.85%

CVSS Scores

Base score Version Severity Vector
1.6 4.0
CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:P/VC:H/VI:N/VA:N/SC:H/SI:H/SA:N/E:U/S:N/AU:N/R:A/V:C/RE:L/U:Green Click to expand
Attack vector (AV:L)
Attacker needs local access on the target system.
Attack complexity (AC:H)
Exploitation depends on constrained or hard-to-reproduce conditions.
Attack requirements (AT:P)
Additional preconditions must be present for exploitation.
Privileges required (PR:L)
Low privileges are required.
User interaction (UI:P)
A user has to participate (for example click/open/approve).
Vulnerable system confidentiality impact (VC:H)
High confidentiality impact on the vulnerable system.
Vulnerable system integrity impact (VI:N)
No integrity impact on the vulnerable system.
Vulnerable system availability impact (VA:N)
No availability impact on the vulnerable system.
Subsequent system confidentiality impact (SC:H)
High confidentiality impact on subsequent systems.
Subsequent system integrity impact (SI:H)
High integrity impact on subsequent systems.
Subsequent system availability impact (SA:N)
No availability impact on subsequent systems.
Exploit maturity (threat) (E:U)
Unreported: no public PoC, no reported exploitation, and no known simplification tools.
Safety (supplemental) (S:N)
Negligible: impact meets the IEC 61508 negligible safety consequence category.
Automatable (supplemental) (AU:N)
No: attackers cannot reliably automate reconnaissance through exploitation for this issue.
Recovery (supplemental) (R:A)
Automatic: services recover on their own after an attack.
Value density (supplemental) (V:C)
Concentrated: a single exploit event controls rich resources (e.g., a central server).
Vulnerability response effort (supplemental) (RE:L)
Low/trivial response effort (documentation, simple configuration, low-touch guidance).
Provider urgency (supplemental) (U:GREEN)
Green: provider rates reduced urgency.

Identifiers

CWEs

CWE id Name
CWE-209 Generation of Error Message Containing Sensitive Information

Affected packages (14)

Vulnerable version ranges and first patched releases as published by GitHub.

Ecosystem Package Vulnerable range First patched Vulnerable functions
maven com.vaadin:flow-plugins >= 23.0.0, < 23.6.10 23.6.11
maven com.vaadin:flow-plugins >= 24.0.0, < 24.9.17 24.9.18
maven com.vaadin:flow-plugins >= 24.10.0, < 24.10.4 24.10.4
maven com.vaadin:flow-plugins >= 25.0.0, < 25.0.11 25.0.12
maven com.vaadin:flow-plugins >= 25.1.0, < 25.1.5 25.1.5
maven com.vaadin:flow-maven-plugin >= 23.0.0, < 23.6.10 23.6.11
maven com.vaadin:flow-maven-plugin >= 24.0.0, < 24.9.17 24.9.18
maven com.vaadin:flow-maven-plugin >= 24.10.0, < 24.10.4 24.10.4
maven com.vaadin:flow-maven-plugin >= 25.0.0, < 25.0.11 25.0.12
maven com.vaadin:flow-maven-plugin >= 25.1.0, < 25.1.5 25.1.5
maven com.vaadin:flow-gradle-plugin >= 24.0.0, < 24.9.17 24.9.18
maven com.vaadin:flow-gradle-plugin >= 24.10.0, < 24.10.4 24.10.4
maven com.vaadin:flow-gradle-plugin >= 25.0.0, < 25.0.11 25.0.12
maven com.vaadin:flow-gradle-plugin >= 25.1.0, < 25.1.5 25.1.5

References

cvelogic Threat Intelligence