Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-10693

Опубликовано: 06 мая 2020
Источник: debian

Описание

A flaw was found in Hibernate Validator version 6.1.2.Final. A bug in the message interpolation processor enables invalid EL expressions to be evaluated as if they were valid. This flaw allows attackers to bypass input sanitation (escaping, stripping) controls that developers may have put in place when handling user-controlled data in error messages.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libhibernate-validator-javaunfixedpackage
libhibernate-validator-javaignoredtrixiepackage
libhibernate-validator-javaignoredbookwormpackage
libhibernate-validator-javano-dsabullseyepackage
libhibernate-validator-javanot-affectedbusterpackage
libhibernate-validator-javanot-affectedstretchpackage
libhibernate-validator-javanot-affectedjessiepackage
libhibernate-validator4-javanot-affectedpackage

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=1805501

Связанные уязвимости

CVSS3: 5.3
ubuntu
почти 6 лет назад

A flaw was found in Hibernate Validator version 6.1.2.Final. A bug in the message interpolation processor enables invalid EL expressions to be evaluated as if they were valid. This flaw allows attackers to bypass input sanitation (escaping, stripping) controls that developers may have put in place when handling user-controlled data in error messages.

CVSS3: 5.3
redhat
почти 6 лет назад

A flaw was found in Hibernate Validator version 6.1.2.Final. A bug in the message interpolation processor enables invalid EL expressions to be evaluated as if they were valid. This flaw allows attackers to bypass input sanitation (escaping, stripping) controls that developers may have put in place when handling user-controlled data in error messages.

CVSS3: 5.3
nvd
почти 6 лет назад

A flaw was found in Hibernate Validator version 6.1.2.Final. A bug in the message interpolation processor enables invalid EL expressions to be evaluated as if they were valid. This flaw allows attackers to bypass input sanitation (escaping, stripping) controls that developers may have put in place when handling user-controlled data in error messages.

CVSS3: 5.3
github
больше 4 лет назад

Improper Input Validation in Hibernate Validator