CVE-2020-10693

Severity
5.3MEDIUM
EPSS
0.3%
top 48.45%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 6
Latest updateJan 15

Description

A flaw was found in Hibernate Validator version 6.1.2.Final. A bug in the message interpolation processor enables invalid EL expressions to be evaluated as if they were valid. This flaw allows attackers to bypass input sanitation (escaping, stripping) controls that developers may have put in place when handling user-controlled data in error messages.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages10 packages

NVDredhat/hibernate_validator5.0.06.0.20+2
Mavenorg.hibernate:hibernate-validator6.1.0.Final6.1.5.Final+1
Mavenorg.hibernate.validator:hibernate-validator6.1.0.Final6.1.5.Final+1
CVEListV5hibernate/hibernate-validator6.1.2.Final
NVDquarkus/quarkus1.4.2

Patches

🔴Vulnerability Details

4
GHSA
Improper Input Validation in Hibernate Validator2021-06-04
OSV
Improper Input Validation in Hibernate Validator2021-06-04
CVEList
CVE-2020-10693: A flaw was found in Hibernate Validator version 62020-05-06
OSV
CVE-2020-10693: A flaw was found in Hibernate Validator version 62020-05-06

📋Vendor Advisories

3
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Third Party Patch (Hibernate Validator) — CVE-2020-106932023-01-15
Red Hat
hibernate-validator: Improper input validation in the interpolation of constraint error messages2020-05-05
Debian
CVE-2020-10693: libhibernate-validator-java - A flaw was found in Hibernate Validator version 6.1.2.Final. A bug in the messag...2020

💬Community

2
Bugzilla
CVE-2020-10693 hibernate-validator: Improper input validation in the interpolation of constraint error messages [fedora-30]2020-05-05
Bugzilla
CVE-2020-10693 hibernate-validator: Improper input validation in the interpolation of constraint error messages2020-02-20