Anti CSRF Token is passed through the GET request during File Upload on Vaadin Framework. This is raising a security issue. The security issues says that on implementing this CSRF Token could be used by someone else though GET Request.
According to the ticket in Vaadin issue tracker this has been addressed in Vaadin 8, has this fix been backported to Vaadin 7?