Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-10219

Опубликовано: 28 авг. 2019
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.

Отчет

Red Hat OpenStack Platform's OpenDaylight will not be updated for this flaw because it is being deprecated and is only receiving security fixes for Important and Critical flaws.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
JBoss Developer Studio 11hibernate-validatorOut of support scope
Red Hat BPM Suite 6hibernate-validatorOut of support scope
Red Hat Decision Manager 7hibernate-validatorNot affected
Red Hat JBoss BRMS 5hibernate-validatorOut of support scope
Red Hat JBoss BRMS 6hibernate-validatorOut of support scope
Red Hat JBoss Data Virtualization 6hibernate-validatorOut of support scope
Red Hat JBoss Enterprise Application Platform 5hibernate-validatorOut of support scope
Red Hat JBoss Enterprise Application Platform 6hibernate-validatorOut of support scope
Red Hat JBoss Fuse 6hibernate-validatorOut of support scope
Red Hat JBoss Fuse Service Works 6hibernate-validatorOut of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=1738673hibernate-validator: safeHTML validator allows XSS

EPSS

Процентиль: 79%
0.01337
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
ubuntu
больше 5 лет назад

A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.

CVSS3: 6.1
nvd
больше 5 лет назад

A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.

CVSS3: 6.1
debian
больше 5 лет назад

A vulnerability was found in Hibernate-Validator. The SafeHtml validat ...

CVSS3: 6.5
github
больше 5 лет назад

The SafeHtml annotation in Hibernate-Validator does not properly guard against XSS attacks

CVSS3: 6.5
fstec
около 6 лет назад

Уязвимость валидатора SafeHtml библиотеки Hibernate Validator, позволяющая нарушителю проводить межсайтовые сценарные атаки

EPSS

Процентиль: 79%
0.01337
Низкий

6.5 Medium

CVSS3