Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-1932

Опубликовано: 07 фев. 2024
Источник: redhat
CVSS3: 6.1
EPSS Низкий

Описание

A flaw was found in hibernate-validator's 'isValid' method in the org.hibernate.validator.internal.constraintvalidators.hv.SafeHtmlValidator class, which can be bypassed by omitting the tag ending in a less-than character. Browsers may render an invalid html, allowing HTML injection or Cross-Site-Scripting (XSS) attacks.

Отчет

Hibernate-validator is packaged with Red Hat OpenStack Platform 13.0's OpenDaylight (ODL). However, because ODL is technical preview in this version and the flaw is moderate, Red Hat will not be releasing a fix for the OpenStack package at this time. Supported versions of Satellite 6 embed vulnerable versions of hibernate-validator inside the candlepin component. However, the vulnerable SafeHtmlValidator functionality is not in use, so it is not possible to exploit it.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
A-MQ Clients 2org.apache.logging.log4j-log4jNot affected
Cryostat 2hibernate-validatorNot affected
Red Hat AMQ Broker 7hibernate-validatorNot affected
Red Hat A-MQ Onlineio.enmasse-enmasseNot affected
Red Hat BPM Suite 6hibernate-validatorOut of support scope
Red Hat CodeReady Studio 12hibernate-validatorAffected
Red Hat Data Grid 8hibernate-validatorNot affected
Red Hat Decision Manager 7hibernate-validatorOut of support scope
Red Hat Fuse 7hibernate-validatorOut of support scope
Red Hat JBoss BRMS 5hibernate-validatorOut of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-1286
https://bugzilla.redhat.com/show_bug.cgi?id=1809444hibernate-validator: rendering of invalid html with SafeHTML leads to HTML injection and XSS

EPSS

Процентиль: 60%
0.00402
Низкий

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
ubuntu
больше 1 года назад

A flaw was found in hibernate-validator's 'isValid' method in the org.hibernate.validator.internal.constraintvalidators.hv.SafeHtmlValidator class, which can be bypassed by omitting the tag ending in a less-than character. Browsers may render an invalid html, allowing HTML injection or Cross-Site-Scripting (XSS) attacks.

CVSS3: 6.1
nvd
больше 1 года назад

A flaw was found in hibernate-validator's 'isValid' method in the org.hibernate.validator.internal.constraintvalidators.hv.SafeHtmlValidator class, which can be bypassed by omitting the tag ending in a less-than character. Browsers may render an invalid html, allowing HTML injection or Cross-Site-Scripting (XSS) attacks.

CVSS3: 6.1
debian
больше 1 года назад

A flaw was found in hibernate-validator's 'isValid' method in the org. ...

CVSS3: 6.1
github
больше 1 года назад

hibernate-validator Cross-site Scripting vulnerability

EPSS

Процентиль: 60%
0.00402
Низкий

6.1 Medium

CVSS3