Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-10693

Опубликовано: 06 мая 2020
Источник: nvd
CVSS3: 5.3
CVSS2: 5
EPSS Низкий

Описание

A flaw was found in Hibernate Validator version 6.1.2.Final. A bug in the message interpolation processor enables invalid EL expressions to be evaluated as if they were valid. This flaw allows attackers to bypass input sanitation (escaping, stripping) controls that developers may have put in place when handling user-controlled data in error messages.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:redhat:hibernate_validator:*:*:*:*:*:*:*:*
Версия от 5.0.0 (включая) до 6.0.20 (исключая)
cpe:2.3:a:redhat:hibernate_validator:*:*:*:*:*:*:*:*
Версия от 6.1.2 (включая) до 6.1.5 (исключая)
cpe:2.3:a:redhat:hibernate_validator:7.0.0:alpha1:*:*:*:*:*:*
Конфигурация 2
cpe:2.3:a:ibm:websphere_application_server:*:*:*:*:liberty:*:*:*
Версия от 17.0.0.3 (включая) до 20.0.0.10 (включая)
Конфигурация 3

Одновременно

Одно из

cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.2.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.3.0:*:*:*:*:*:*:*

Одно из

cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
Конфигурация 4

Одно из

cpe:2.3:a:redhat:satellite:6.8:*:*:*:*:*:*:*
cpe:2.3:a:redhat:satellite_capsule:6.8:*:*:*:*:*:*:*
Конфигурация 5
cpe:2.3:a:quarkus:quarkus:*:*:*:*:*:*:*:*
Версия до 1.4.2 (включая)
Конфигурация 6
cpe:2.3:a:oracle:weblogic_server:14.1.1.0.0:*:*:*:*:*:*:*

EPSS

Процентиль: 82%
0.02294
Низкий

5.3 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-20
CWE-20

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 6 лет назад

A flaw was found in Hibernate Validator version 6.1.2.Final. A bug in the message interpolation processor enables invalid EL expressions to be evaluated as if they were valid. This flaw allows attackers to bypass input sanitation (escaping, stripping) controls that developers may have put in place when handling user-controlled data in error messages.

CVSS3: 5.3
redhat
больше 6 лет назад

A flaw was found in Hibernate Validator version 6.1.2.Final. A bug in the message interpolation processor enables invalid EL expressions to be evaluated as if they were valid. This flaw allows attackers to bypass input sanitation (escaping, stripping) controls that developers may have put in place when handling user-controlled data in error messages.

CVSS3: 5.3
debian
больше 6 лет назад

A flaw was found in Hibernate Validator version 6.1.2.Final. A bug in ...

CVSS3: 5.3
github
около 5 лет назад

Improper Input Validation in Hibernate Validator

EPSS

Процентиль: 82%
0.02294
Низкий

5.3 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-20
CWE-20