Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-7536

Опубликовано: 10 янв. 2018
Источник: debian
EPSS Низкий

Описание

In Hibernate Validator 5.2.x before 5.2.5 final, 5.3.x, and 5.4.x, it was found that when the security manager's reflective permissions, which allows it to access the private members of the class, are granted to Hibernate Validator, a potential privilege escalation can occur. By allowing the calling code to access those private members without the permission an attacker may be able to validate an invalid instance and access the private member value via ConstraintViolation#getInvalidValue().

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libhibernate-validator-javafixed4.3.3-4package
libhibernate-validator-javafixed4.3.3-1+deb9u1stretchpackage
libhibernate-validator-javanot-affectedjessiepackage
libhibernate-validator-javanot-affectedwheezypackage

Примечания

  • https://github.com/hibernate/hibernate-validator/commit/0ed45f37c4680998167179e631113a2c9cb5d113

  • https://bugzilla.redhat.com/show_bug.cgi?id=1465573

EPSS

Процентиль: 29%
0.00104
Низкий

Связанные уязвимости

CVSS3: 7
ubuntu
больше 7 лет назад

In Hibernate Validator 5.2.x before 5.2.5 final, 5.3.x, and 5.4.x, it was found that when the security manager's reflective permissions, which allows it to access the private members of the class, are granted to Hibernate Validator, a potential privilege escalation can occur. By allowing the calling code to access those private members without the permission an attacker may be able to validate an invalid instance and access the private member value via ConstraintViolation#getInvalidValue().

CVSS3: 6.3
redhat
почти 8 лет назад

In Hibernate Validator 5.2.x before 5.2.5 final, 5.3.x, and 5.4.x, it was found that when the security manager's reflective permissions, which allows it to access the private members of the class, are granted to Hibernate Validator, a potential privilege escalation can occur. By allowing the calling code to access those private members without the permission an attacker may be able to validate an invalid instance and access the private member value via ConstraintViolation#getInvalidValue().

CVSS3: 7
nvd
больше 7 лет назад

In Hibernate Validator 5.2.x before 5.2.5 final, 5.3.x, and 5.4.x, it was found that when the security manager's reflective permissions, which allows it to access the private members of the class, are granted to Hibernate Validator, a potential privilege escalation can occur. By allowing the calling code to access those private members without the permission an attacker may be able to validate an invalid instance and access the private member value via ConstraintViolation#getInvalidValue().

CVSS3: 7
github
около 5 лет назад

Privilege Escalation in Hibernate Validator

EPSS

Процентиль: 29%
0.00104
Низкий