CVE-2019-10219
published 2019-11-08CVE-2019-10219: A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious…
PriorityP428medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
2.17%
80.2th percentile
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
Affected
404 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libhibernate-validator-java | — | — |
| debian | libhibernate-validator4-java | — | — |
| hibernate | hibernate-validator | 6.0.0.Alpha1 – 6.0.17.Final | — |
| hibernate | hibernate-validator | 6.1.0.Alpha1 – 6.1.0.Alpha6 | — |
| oracle | access_manager | — | — |
| oracle | access_manager | — | — |
| oracle | access_manager | — | — |
| oracle | agile_engineering_data_management | — | — |
| oracle | agile_plm | — | — |
| oracle | agile_plm | — | — |
| oracle | agile_product_lifecycle_analytics | — | — |
| oracle | agile_product_lifecycle_management_integration_pack | — | — |
| oracle | airlines_data_model | — | — |
| oracle | airlines_data_model | — | — |
| oracle | application_express | — | — |
| oracle | application_performance_management | — | — |
| oracle | application_performance_management | — | — |
| oracle | application_testing_suite | — | — |
| oracle | argus_analytics | — | — |
| oracle | argus_analytics | — | — |
| oracle | argus_analytics | — | — |
| oracle | argus_analytics | — | — |
| oracle | argus_insight | — | — |
| oracle | argus_insight | — | — |
| oracle | argus_insight | — | — |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv6.1MEDIUM
vendor_debian6.1MEDIUM
vendor_oracle6.1MEDIUM
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Web Services (JBoss Enterprise Application Platform) — CVE-2019-10219
vendor_oracle·2022-01-15·CVSS 6.1
CVE-2019-10219 [MEDIUM] Oracle Oracle Fusion Middleware Risk Matrix: Web Services (JBoss Enterprise Application Platform) — CVE-2019-10219
Oracle Oracle Fusion Middleware Risk Matrix: Web Services (JBoss Enterprise Application Platform) vulnerability
CVE: CVE-2019-10219
CVSS: 6.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2022 (JAN 2022)
Red Hat
hibernate-validator: safeHTML validator allows XSS
vendor_redhat·2019-08-28·CVSS 6.1
CVE-2019-10219 [MEDIUM] CWE-79 hibernate-validator: safeHTML validator allows XSS
hibernate-validator: safeHTML validator allows XSS
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
Statement: Red Hat OpenStack Platform's OpenDaylight will not be updated for this flaw because it is being deprecated and is only receiving security fixes for Important and Critical flaws.
Package: hibernate-validator (JBoss Developer Studio 11) - Out of su
Debian
CVE-2019-10219: libhibernate-validator-java - A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotat...
vendor_debian·2019·CVSS 6.1
CVE-2019-10219 [MEDIUM] CVE-2019-10219: libhibernate-validator-java - A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotat...
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
OSV
The SafeHtml annotation in Hibernate-Validator does not properly guard against XSS attacks
osv·2020-01-08
CVE-2019-10219 [MEDIUM] The SafeHtml annotation in Hibernate-Validator does not properly guard against XSS attacks
The SafeHtml annotation in Hibernate-Validator does not properly guard against XSS attacks
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
GHSA
The SafeHtml annotation in Hibernate-Validator does not properly guard against XSS attacks
ghsa·2020-01-08
CVE-2019-10219 [MEDIUM] CWE-79 The SafeHtml annotation in Hibernate-Validator does not properly guard against XSS attacks
The SafeHtml annotation in Hibernate-Validator does not properly guard against XSS attacks
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
OSV
CVE-2019-10219: A vulnerability was found in Hibernate-Validator
osv·2019-11-08·CVSS 6.1
CVE-2019-10219 [MEDIUM] CVE-2019-10219: A vulnerability was found in Hibernate-Validator
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
No detection rules found.
No public exploits indexed.
https://access.redhat.com/errata/RHSA-2020:0159https://access.redhat.com/errata/RHSA-2020:0160https://access.redhat.com/errata/RHSA-2020:0161https://access.redhat.com/errata/RHSA-2020:0164https://access.redhat.com/errata/RHSA-2020:0445https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10219https://github.com/hibernate/hibernate-validator/commit/124b7dd6d9a4ad24d4d49f74701f05a13e56ceehttps://github.com/hibernate/hibernate-validator/commit/20d729548511ac5cff6fd459f93de137195420fehttps://github.com/poc-effectiveness/PoCAdaptation/tree/main/Adapted/CVE-2019-10219https://github.com/poc-effectiveness/PoCAdaptation/tree/main/Origin/CVE-2019-10219/exploithttps://lists.apache.org/thread.html/r4f8b4e2541be4234946e40d55859273a7eec0f4901e8080ce2406fe6%40%3Cnotifications.accumulo.apache.org%3Ehttps://lists.apache.org/thread.html/r4f92d7f7682dcff92722fa947f9e6f8ba2227c5dc3e11ba09114897d%40%3Cnotifications.accumulo.apache.org%3Ehttps://lists.apache.org/thread.html/r87b7e2d22982b4ca9f88f5f4f22a19b394d2662415b233582ed22ebf%40%3Cnotifications.accumulo.apache.org%3Ehttps://lists.apache.org/thread.html/rb8dca19a4e52b60dab0ab21e2ff9968d78f4b84e4033824db1dd24b4%40%3Cpluto-scm.portals.apache.org%3Ehttps://lists.apache.org/thread.html/rd418deda6f0ebe658c2015f43a14d03acb8b8c2c093c5bf6b880cd7c%40%3Cpluto-dev.portals.apache.org%3Ehttps://lists.apache.org/thread.html/rf9c17c3efc4a376a96e9e2777eee6acf0bec28e2200e4b35da62de4a%40%3Cpluto-dev.portals.apache.org%3Ehttps://security.netapp.com/advisory/ntap-20220210-0024/https://www.oracle.com/security-alerts/cpujan2022.htmlhttps://access.redhat.com/errata/RHSA-2020:0159https://access.redhat.com/errata/RHSA-2020:0160https://access.redhat.com/errata/RHSA-2020:0161https://access.redhat.com/errata/RHSA-2020:0164https://access.redhat.com/errata/RHSA-2020:0445https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10219https://github.com/hibernate/hibernate-validator/commit/124b7dd6d9a4ad24d4d49f74701f05a13e56ceeehttps://github.com/hibernate/hibernate-validator/commit/20d729548511ac5cff6fd459f93de137195420fehttps://github.com/poc-effectiveness/PoCAdaptation/tree/main/Adapted/CVE-2019-10219https://github.com/poc-effectiveness/PoCAdaptation/tree/main/Origin/CVE-2019-10219/exploithttps://lists.apache.org/thread.html/r4f8b4e2541be4234946e40d55859273a7eec0f4901e8080ce2406fe6%40%3Cnotifications.accumulo.apache.org%3Ehttps://lists.apache.org/thread.html/r4f92d7f7682dcff92722fa947f9e6f8ba2227c5dc3e11ba09114897d%40%3Cnotifications.accumulo.apache.org%3Ehttps://lists.apache.org/thread.html/r87b7e2d22982b4ca9f88f5f4f22a19b394d2662415b233582ed22ebf%40%3Cnotifications.accumulo.apache.org%3Ehttps://lists.apache.org/thread.html/rb8dca19a4e52b60dab0ab21e2ff9968d78f4b84e4033824db1dd24b4%40%3Cpluto-scm.portals.apache.org%3Ehttps://lists.apache.org/thread.html/rd418deda6f0ebe658c2015f43a14d03acb8b8c2c093c5bf6b880cd7c%40%3Cpluto-dev.portals.apache.org%3Ehttps://lists.apache.org/thread.html/rf9c17c3efc4a376a96e9e2777eee6acf0bec28e2200e4b35da62de4a%40%3Cpluto-dev.portals.apache.org%3Ehttps://security.netapp.com/advisory/ntap-20220210-0024/https://www.oracle.com/security-alerts/cpujan2022.html
2019-11-08
Published