All vulnerability reports

Missing sheet protection check when updating cell comments

Overview

The handler that updates a cell comment in the Vaadin Spreadsheet component did not re-check the sheet protection state, so a user of an application that renders a spreadsheet could add or replace comments on a protected sheet and on locked cells, and create empty cells in the process.


See CWE-285: Improper Authorization

Description

The Spreadsheet component enforces sheet protection on the server, because the client is not trusted to enforce it. The handlers for editing a cell value, deleting the selected cells and both branches of the paste operation all re-check the protection state with Spreadsheet.isCellLocked(...) and report a protected write attempt instead of touching the workbook.

The handler that updates a cell comment did not perform that check. It resolved the target cell and wrote the comment text directly. That handler is reachable from the browser through the DOM event the client uses for all Spreadsheet remote calls, and the dispatch applies no authorization of its own, so a user can send a comment update for any cell of the active sheet, including locked cells, and the server performs the write. Because the cell is resolved with a get-or-create call, a comment aimed at an empty cell also creates the row and the cell.

The component's own user interface never offers comment editing while a sheet is protected, so exploiting this means dispatching the client event directly. No special application configuration is required.

The impact is limited to the integrity of comment text and to the creation of empty cells, in the workbook held in the user's own session. It reaches other users when the application persists the workbook or shares the Spreadsheet instance, which is the usual pattern for applications that enable sheet protection. Confidentiality and availability are not affected.

The Spreadsheet add-on for Vaadin Framework 7 and 8 has the same flaw in its own comment handler and is fixed in add-on version 3.1.1.

The fix applies the same check the other write handlers use, before the target cell is resolved, so no row or cell is created either.

Affected products and mitigation

Users of affected versions should apply the following mitigation or upgrade. Releases that have fixed this issue include:
Product version Mitigation
Vaadin 23.1.0 - 23.6.13
Upgrade to 23.6.14
Vaadin 24.0.0 - 24.9.21
Upgrade to 24.9.22
Vaadin 24.10.0 - 24.10.9
Upgrade to 24.10.10
Vaadin 25.0.0 - 25.1.11
Upgrade to 25.1.12
Vaadin 25.2.0 - 25.2.6 Upgrade to 25.2.7 or newer
Vaadin Spreadsheet add-on 2.0.0 - 3.1.0
Upgrade to 3.1.1

Vaadin 23.0.x is not affected, as the Spreadsheet component was first published for that line in 23.1.0. Vaadin 14 is not affected either, as the Spreadsheet component was not supported there.

Please note that Vaadin versions 10-13 and 15-22 are no longer supported and you should update either to the latest 23, 24, 25 version.

Artifacts

Maven coordinates Vulnerable version Fixed version
com.vaadin:vaadin 23.1.0 - 23.6.13 ≥23.6.14
com.vaadin:vaadin 24.0.0 - 24.9.21 ≥24.9.22
com.vaadin:vaadin 24.10.0 - 24.10.9 ≥24.10.10
com.vaadin:vaadin 25.0.0 - 25.1.11 ≥25.1.12
com.vaadin:vaadin
25.2.0 - 25.2.6
≥25.2.7
com.vaadin:vaadin-spreadsheet-flow 23.1.0 - 23.6.13 ≥23.6.14
com.vaadin:vaadin-spreadsheet-flow
24.0.0 - 24.9.21
≥24.9.22
com.vaadin:vaadin-spreadsheet-flow
24.10.0 - 24.10.9
≥24.10.10
com.vaadin:vaadin-spreadsheet-flow
25.0.0 - 25.1.11
≥25.1.12
com.vaadin:vaadin-spreadsheet-flow
25.2.0 - 25.2.6
≥25.2.7
com.vaadin:vaadin-spreadsheet
2.0.0 - 3.1.0
≥3.1.1

com.vaadin:vaadin-spreadsheet is the Spreadsheet add-on for Vaadin Framework 7 and 8. It has its own version numbering and is published to https://maven.vaadin.com/vaadin-addons  rather than to Maven Central.

 

References

Credit

Reported by Arpit Jain.

History

  • 2026-09-30: Initial vulnerability report published