Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rmrm-75hp-phr2

Опубликовано: 04 июн. 2021
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

Improper Input Validation in Hibernate Validator

A flaw was found in Hibernate Validator version 6.1.2.Final. A bug in the message interpolation processor enables invalid EL expressions to be evaluated as if they were valid. This flaw allows attackers to bypass input sanitation (escaping, stripping) controls that developers may have put in place when handling user-controlled data in error messages.

Пакеты

Наименование

org.hibernate.validator:hibernate-validator

maven
Затронутые версииВерсия исправления

>= 6.1.0.Final, <= 6.1.4.Final

6.1.5.Final

Наименование

org.hibernate.validator:hibernate-validator

maven
Затронутые версииВерсия исправления

<= 6.0.19.Final

6.0.20.Final

Наименование

org.hibernate:hibernate-validator

maven
Затронутые версииВерсия исправления

>= 6.1.0.Final, <= 6.1.4.Final

6.1.5.Final

Наименование

org.hibernate:hibernate-validator

maven
Затронутые версииВерсия исправления

<= 6.0.19.Final

6.0.20.Final

EPSS

Процентиль: 52%
0.00293
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 5.3
ubuntu
почти 6 лет назад

A flaw was found in Hibernate Validator version 6.1.2.Final. A bug in the message interpolation processor enables invalid EL expressions to be evaluated as if they were valid. This flaw allows attackers to bypass input sanitation (escaping, stripping) controls that developers may have put in place when handling user-controlled data in error messages.

CVSS3: 5.3
redhat
почти 6 лет назад

A flaw was found in Hibernate Validator version 6.1.2.Final. A bug in the message interpolation processor enables invalid EL expressions to be evaluated as if they were valid. This flaw allows attackers to bypass input sanitation (escaping, stripping) controls that developers may have put in place when handling user-controlled data in error messages.

CVSS3: 5.3
nvd
почти 6 лет назад

A flaw was found in Hibernate Validator version 6.1.2.Final. A bug in the message interpolation processor enables invalid EL expressions to be evaluated as if they were valid. This flaw allows attackers to bypass input sanitation (escaping, stripping) controls that developers may have put in place when handling user-controlled data in error messages.

CVSS3: 5.3
debian
почти 6 лет назад

A flaw was found in Hibernate Validator version 6.1.2.Final. A bug in ...

EPSS

Процентиль: 52%
0.00293
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-20