Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x83m-pf6f-pf9g

Опубликовано: 07 нояб. 2024
Источник: github
Github: Прошло ревью
CVSS4: 5.3
CVSS3: 6.1

Описание

hibernate-validator Cross-site Scripting vulnerability

A flaw was found in hibernate-validator's 'isValid' method in the org.hibernate.validator.internal.constraintvalidators.hv.SafeHtmlValidator class, which can be bypassed by omitting the tag ending in a less-than character. Browsers may render an invalid html, allowing HTML injection or Cross-Site-Scripting (XSS) attacks.

Пакеты

Наименование

org.hibernate.validator:hibernate-validator

maven
Затронутые версииВерсия исправления

< 6.2.0.Final

6.2.0.Final

Наименование

org.hibernate:hibernate-validator

maven
Затронутые версииВерсия исправления

< 6.2.0.Final

6.2.0.Final

EPSS

Процентиль: 52%
0.00296
Низкий

5.3 Medium

CVSS4

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
ubuntu
больше 1 года назад

A flaw was found in hibernate-validator's 'isValid' method in the org.hibernate.validator.internal.constraintvalidators.hv.SafeHtmlValidator class, which can be bypassed by omitting the tag ending in a less-than character. Browsers may render an invalid html, allowing HTML injection or Cross-Site-Scripting (XSS) attacks.

CVSS3: 6.1
redhat
около 2 лет назад

A flaw was found in hibernate-validator's 'isValid' method in the org.hibernate.validator.internal.constraintvalidators.hv.SafeHtmlValidator class, which can be bypassed by omitting the tag ending in a less-than character. Browsers may render an invalid html, allowing HTML injection or Cross-Site-Scripting (XSS) attacks.

CVSS3: 6.1
nvd
больше 1 года назад

A flaw was found in hibernate-validator's 'isValid' method in the org.hibernate.validator.internal.constraintvalidators.hv.SafeHtmlValidator class, which can be bypassed by omitting the tag ending in a less-than character. Browsers may render an invalid html, allowing HTML injection or Cross-Site-Scripting (XSS) attacks.

CVSS3: 6.1
debian
больше 1 года назад

A flaw was found in hibernate-validator's 'isValid' method in the org. ...

EPSS

Процентиль: 52%
0.00296
Низкий

5.3 Medium

CVSS4

6.1 Medium

CVSS3

Дефекты

CWE-79