Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-10693

Опубликовано: 05 мая 2020
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

A flaw was found in Hibernate Validator version 6.1.2.Final. A bug in the message interpolation processor enables invalid EL expressions to be evaluated as if they were valid. This flaw allows attackers to bypass input sanitation (escaping, stripping) controls that developers may have put in place when handling user-controlled data in error messages.

Отчет

hibernate-validator is packaged with Red Hat OpenStack Platform 13.0's OpenDaylight (ODL). However, because ODL is technical preview in this version and the flaw is moderate, Red Hat will not be releasing a fix for the OpenStack package at this time.

Меры по смягчению последствий

You can pass user input as an expression variable by unwrapping the context to HibernateConstraintValidatorContext. Please refer to the https://in.relation.to/2020/05/07/hibernate-validator-615-6020-released/ and https://docs.jboss.org/hibernate/stable/validator/reference/en-US/html_single/#_the_code_constraintvalidatorcontext_code.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat BPM Suite 6hibernate-validatorOut of support scope
Red Hat CodeReady Studio 12hibernate-validatorAffected
Red Hat Data Grid 8hibernate-validatorNot affected
Red Hat JBoss BRMS 5hibernate-validatorOut of support scope
Red Hat JBoss Data Grid 7hibernate-validatorOut of support scope
Red Hat JBoss Data Virtualization 6hibernate-validatorOut of support scope
Red Hat JBoss Enterprise Application Platform 5hibernate-validatorOut of support scope
Red Hat JBoss Enterprise Application Platform 6hibernate-validatorOut of support scope
Red Hat JBoss Fuse 6hibernate-validatorOut of support scope
Red Hat JBoss Fuse Service Works 6hibernate-validatorOut of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1805501hibernate-validator: Improper input validation in the interpolation of constraint error messages

EPSS

Процентиль: 52%
0.00293
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
почти 6 лет назад

A flaw was found in Hibernate Validator version 6.1.2.Final. A bug in the message interpolation processor enables invalid EL expressions to be evaluated as if they were valid. This flaw allows attackers to bypass input sanitation (escaping, stripping) controls that developers may have put in place when handling user-controlled data in error messages.

CVSS3: 5.3
nvd
почти 6 лет назад

A flaw was found in Hibernate Validator version 6.1.2.Final. A bug in the message interpolation processor enables invalid EL expressions to be evaluated as if they were valid. This flaw allows attackers to bypass input sanitation (escaping, stripping) controls that developers may have put in place when handling user-controlled data in error messages.

CVSS3: 5.3
debian
почти 6 лет назад

A flaw was found in Hibernate Validator version 6.1.2.Final. A bug in ...

CVSS3: 5.3
github
больше 4 лет назад

Improper Input Validation in Hibernate Validator

EPSS

Процентиль: 52%
0.00293
Низкий

5.3 Medium

CVSS3

Уязвимость CVE-2020-10693