Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-10219

Опубликовано: 08 нояб. 2019
Источник: debian
EPSS Низкий

Описание

A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libhibernate-validator-javaunfixedpackage
libhibernate-validator-javaignoredtrixiepackage
libhibernate-validator-javaignoredbookwormpackage
libhibernate-validator-javano-dsabullseyepackage
libhibernate-validator-javanot-affectedbusterpackage
libhibernate-validator-javanot-affectedstretchpackage
libhibernate-validator-javanot-affectedjessiepackage
libhibernate-validator4-javanot-affectedpackage

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=1738673

  • https://hibernate.atlassian.net/browse/HV-1739

  • Fixed by https://github.com/hibernate/hibernate-validator/commit/124b7dd6d9a4ad24d4d49f74701f05a13e56ceee

EPSS

Процентиль: 79%
0.01337
Низкий

Связанные уязвимости

CVSS3: 6.1
ubuntu
больше 5 лет назад

A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.

CVSS3: 6.5
redhat
почти 6 лет назад

A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.

CVSS3: 6.1
nvd
больше 5 лет назад

A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.

CVSS3: 6.5
github
больше 5 лет назад

The SafeHtml annotation in Hibernate-Validator does not properly guard against XSS attacks

CVSS3: 6.5
fstec
около 6 лет назад

Уязвимость валидатора SafeHtml библиотеки Hibernate Validator, позволяющая нарушителю проводить межсайтовые сценарные атаки

EPSS

Процентиль: 79%
0.01337
Низкий