Описание
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
Отчет
Red Hat OpenStack Platform's OpenDaylight will not be updated for this flaw because it is being deprecated and is only receiving security fixes for Important and Critical flaws.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
JBoss Developer Studio 11 | hibernate-validator | Out of support scope | ||
Red Hat BPM Suite 6 | hibernate-validator | Out of support scope | ||
Red Hat Decision Manager 7 | hibernate-validator | Not affected | ||
Red Hat JBoss BRMS 5 | hibernate-validator | Out of support scope | ||
Red Hat JBoss BRMS 6 | hibernate-validator | Out of support scope | ||
Red Hat JBoss Data Virtualization 6 | hibernate-validator | Out of support scope | ||
Red Hat JBoss Enterprise Application Platform 5 | hibernate-validator | Out of support scope | ||
Red Hat JBoss Enterprise Application Platform 6 | hibernate-validator | Out of support scope | ||
Red Hat JBoss Fuse 6 | hibernate-validator | Out of support scope | ||
Red Hat JBoss Fuse Service Works 6 | hibernate-validator | Out of support scope |
Показывать по
Дополнительная информация
Статус:
EPSS
6.5 Medium
CVSS3
Связанные уязвимости
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
A vulnerability was found in Hibernate-Validator. The SafeHtml validat ...
The SafeHtml annotation in Hibernate-Validator does not properly guard against XSS attacks
Уязвимость валидатора SafeHtml библиотеки Hibernate Validator, позволяющая нарушителю проводить межсайтовые сценарные атаки
EPSS
6.5 Medium
CVSS3