Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8grg-q944-cch5

Опубликовано: 10 фев. 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

SQL Injection in Hibernate ORM

A flaw was found in Hibernate ORM in versions before 5.3.18, 5.4.18 and 5.5.0.Beta1. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SELECT or GROUP BY parts of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks.

Пакеты

Наименование

org.hibernate:hibernate-core

maven
Затронутые версииВерсия исправления

< 5.3.18

5.3.18

Наименование

org.hibernate:hibernate-core

maven
Затронутые версииВерсия исправления

>= 5.4.0, < 5.4.18

5.4.18

Наименование

org.hibernate:hibernate-core

maven
Затронутые версииВерсия исправления

>= 5.5.0.Alpha1, < 5.5.0.Beta1

5.5.0.Beta1

EPSS

Процентиль: 80%
0.01405
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 6.5
redhat
больше 5 лет назад

A flaw was found in Hibernate ORM in versions before 5.3.18, 5.4.18 and 5.5.0.Beta1. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SELECT or GROUP BY parts of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks.

CVSS3: 6.5
nvd
больше 5 лет назад

A flaw was found in Hibernate ORM in versions before 5.3.18, 5.4.18 and 5.5.0.Beta1. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SELECT or GROUP BY parts of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks.

CVSS3: 6.5
debian
больше 5 лет назад

A flaw was found in Hibernate ORM in versions before 5.3.18, 5.4.18 an ...

EPSS

Процентиль: 80%
0.01405
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-89