Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-1932

Опубликовано: 07 нояб. 2024
Источник: debian

Описание

A flaw was found in hibernate-validator's 'isValid' method in the org.hibernate.validator.internal.constraintvalidators.hv.SafeHtmlValidator class, which can be bypassed by omitting the tag ending in a less-than character. Browsers may render an invalid html, allowing HTML injection or Cross-Site-Scripting (XSS) attacks.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libhibernate-validator-javaunfixedpackage
libhibernate-validator-javaignoredtrixiepackage
libhibernate-validator-javaignoredbookwormpackage
libhibernate-validator-javano-dsabullseyepackage
libhibernate-validator-javano-dsabusterpackage

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=1809444

Связанные уязвимости

CVSS3: 6.1
ubuntu
больше 1 года назад

A flaw was found in hibernate-validator's 'isValid' method in the org.hibernate.validator.internal.constraintvalidators.hv.SafeHtmlValidator class, which can be bypassed by omitting the tag ending in a less-than character. Browsers may render an invalid html, allowing HTML injection or Cross-Site-Scripting (XSS) attacks.

CVSS3: 6.1
redhat
около 2 лет назад

A flaw was found in hibernate-validator's 'isValid' method in the org.hibernate.validator.internal.constraintvalidators.hv.SafeHtmlValidator class, which can be bypassed by omitting the tag ending in a less-than character. Browsers may render an invalid html, allowing HTML injection or Cross-Site-Scripting (XSS) attacks.

CVSS3: 6.1
nvd
больше 1 года назад

A flaw was found in hibernate-validator's 'isValid' method in the org.hibernate.validator.internal.constraintvalidators.hv.SafeHtmlValidator class, which can be bypassed by omitting the tag ending in a less-than character. Browsers may render an invalid html, allowing HTML injection or Cross-Site-Scripting (XSS) attacks.

CVSS3: 6.1
github
больше 1 года назад

hibernate-validator Cross-site Scripting vulnerability