cbcvebase.
CVE-2020-10693
published 2020-05-06

CVE-2020-10693: A flaw was found in Hibernate Validator version 6.1.2.Final. A bug in the message interpolation processor enables invalid EL expressions to be evaluated as if…

medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
A flaw was found in Hibernate Validator version 6.1.2.Final. A bug in the message interpolation processor enables invalid EL expressions to be evaluated as if they were valid. This flaw allows attackers to bypass input sanitation (escaping, stripping) controls that developers may have put in place when handling user-controlled data in error messages.

Affected

13 ranges
VendorProductVersion rangeFixed in
debianlibhibernate-validator-java
debianlibhibernate-validator4-java
hibernatehibernate-validator
ibmwebsphere_application_server17.0.0.3 – 20.0.0.10
oracleweblogic_server
quarkusquarkus<= 1.4.2
redhathibernate_validator
redhathibernate_validator>= 5.0.0 < 6.0.206.0.20
redhathibernate_validator>= 6.1.2 < 6.1.56.1.5
redhatjboss_enterprise_application_platform
redhatjboss_enterprise_application_platform
redhatsatellite
redhatsatellite_capsule

CVSS provenance

nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
osv5.3MEDIUM