Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m8p2-495h-ccmh

Опубликовано: 08 янв. 2020
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

The SafeHtml annotation in Hibernate-Validator does not properly guard against XSS attacks

A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.

Ссылки

Пакеты

Наименование

org.hibernate.validator:hibernate-validator

maven
Затронутые версииВерсия исправления

>= 6.1.0.Alpha1, < 6.1.0.Alpha6

6.1.0.Alpha6

Наименование

org.hibernate.validator:hibernate-validator

maven
Затронутые версииВерсия исправления

>= 6.0.0.Alpha1, <= 6.0.17.Final

6.0.18.Final

Наименование

org.hibernate:hibernate-validator

maven
Затронутые версииВерсия исправления

>= 6.1.0.Alpha1, < 6.1.0.Alpha6

6.1.0.Alpha6

Наименование

org.hibernate:hibernate-validator

maven
Затронутые версииВерсия исправления

>= 6.0.0.Alpha1, <= 6.0.17.Final

6.0.18.Final

EPSS

Процентиль: 82%
0.01674
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
ubuntu
почти 6 лет назад

A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.

CVSS3: 6.5
redhat
около 6 лет назад

A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.

CVSS3: 6.1
nvd
почти 6 лет назад

A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.

CVSS3: 6.1
debian
почти 6 лет назад

A vulnerability was found in Hibernate-Validator. The SafeHtml validat ...

CVSS3: 6.5
fstec
больше 6 лет назад

Уязвимость валидатора SafeHtml библиотеки Hibernate Validator, позволяющая нарушителю проводить межсайтовые сценарные атаки

EPSS

Процентиль: 82%
0.01674
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-79