CVE-2020-10693
published 2020-05-06CVE-2020-10693: A flaw was found in Hibernate Validator version 6.1.2.Final. A bug in the message interpolation processor enables invalid EL expressions to be evaluated as if…
PriorityP428medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
2.29%
81.3th percentile
A flaw was found in Hibernate Validator version 6.1.2.Final. A bug in the message interpolation processor enables invalid EL expressions to be evaluated as if they were valid. This flaw allows attackers to bypass input sanitation (escaping, stripping) controls that developers may have put in place when handling user-controlled data in error messages.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libhibernate-validator-java | — | — |
| debian | libhibernate-validator4-java | — | — |
| hibernate | hibernate-validator | — | — |
| ibm | websphere_application_server | 17.0.0.3 – 20.0.0.10 | — |
| oracle | weblogic_server | — | — |
| quarkus | quarkus | <= 1.4.2 | — |
| redhat | hibernate_validator | — | — |
| redhat | hibernate_validator | >= 5.0.0 < 6.0.20 | 6.0.20 |
| redhat | hibernate_validator | >= 6.1.2 < 6.1.5 | 6.1.5 |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | satellite | — | — |
| redhat | satellite_capsule | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv5.3MEDIUM
vendor_debian5.3MEDIUM
vendor_oracle5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Third Party Patch (Hibernate Validator) — CVE-2020-10693
vendor_oracle·2023-01-15·CVSS 5.3
CVE-2020-10693 [MEDIUM] Oracle Oracle Fusion Middleware Risk Matrix: Third Party Patch (Hibernate Validator) — CVE-2020-10693
Oracle Oracle Fusion Middleware Risk Matrix: Third Party Patch (Hibernate Validator) vulnerability
CVE: CVE-2020-10693
CVSS: 5.3
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2023 (JAN 2023)
Red Hat
hibernate-validator: Improper input validation in the interpolation of constraint error messages
vendor_redhat·2020-05-05·CVSS 5.3
CVE-2020-10693 [MEDIUM] CWE-20 hibernate-validator: Improper input validation in the interpolation of constraint error messages
hibernate-validator: Improper input validation in the interpolation of constraint error messages
A flaw was found in Hibernate Validator version 6.1.2.Final. A bug in the message interpolation processor enables invalid EL expressions to be evaluated as if they were valid. This flaw allows attackers to bypass input sanitation (escaping, stripping) controls that developers may have put in place when handling user-controlled data in error messages.
A flaw was found in Hibernate Validator version 6.1.2.Final. A bug in the message interpolation processor enables invalid EL expressions to be evaluated as if they were valid. This flaw allows attackers to bypass input sanitation (escaping, stripping) controls that developers may have put in place when handling user-controlled data in error messa
Debian
CVE-2020-10693: libhibernate-validator-java - A flaw was found in Hibernate Validator version 6.1.2.Final. A bug in the messag...
vendor_debian·2020·CVSS 5.3
CVE-2020-10693 [MEDIUM] CVE-2020-10693: libhibernate-validator-java - A flaw was found in Hibernate Validator version 6.1.2.Final. A bug in the messag...
A flaw was found in Hibernate Validator version 6.1.2.Final. A bug in the message interpolation processor enables invalid EL expressions to be evaluated as if they were valid. This flaw allows attackers to bypass input sanitation (escaping, stripping) controls that developers may have put in place when handling user-controlled data in error messages.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
GHSA
Improper Input Validation in Hibernate Validator
ghsa·2021-06-04
CVE-2020-10693 [MEDIUM] CWE-20 Improper Input Validation in Hibernate Validator
Improper Input Validation in Hibernate Validator
A flaw was found in Hibernate Validator version 6.1.2.Final. A bug in the message interpolation processor enables invalid EL expressions to be evaluated as if they were valid. This flaw allows attackers to bypass input sanitation (escaping, stripping) controls that developers may have put in place when handling user-controlled data in error messages.
OSV
Improper Input Validation in Hibernate Validator
osv·2021-06-04
CVE-2020-10693 [MEDIUM] Improper Input Validation in Hibernate Validator
Improper Input Validation in Hibernate Validator
A flaw was found in Hibernate Validator version 6.1.2.Final. A bug in the message interpolation processor enables invalid EL expressions to be evaluated as if they were valid. This flaw allows attackers to bypass input sanitation (escaping, stripping) controls that developers may have put in place when handling user-controlled data in error messages.
OSV
CVE-2020-10693: A flaw was found in Hibernate Validator version 6
osv·2020-05-06·CVSS 5.3
CVE-2020-10693 [MEDIUM] CVE-2020-10693: A flaw was found in Hibernate Validator version 6
A flaw was found in Hibernate Validator version 6.1.2.Final. A bug in the message interpolation processor enables invalid EL expressions to be evaluated as if they were valid. This flaw allows attackers to bypass input sanitation (escaping, stripping) controls that developers may have put in place when handling user-controlled data in error messages.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-10693 hibernate-validator: Improper input validation in the interpolation of constraint error messages [fedora-30]
bugzilla·2020-05-05·CVSS 5.3
CVE-2020-10693 [MEDIUM] CVE-2020-10693 hibernate-validator: Improper input validation in the interpolation of constraint error messages [fedora-30]
CVE-2020-10693 hibernate-validator: Improper input validation in the interpolation of constraint error messages [fedora-30]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-30.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discus
Bugzilla
CVE-2020-10693 hibernate-validator: Improper input validation in the interpolation of constraint error messages
bugzilla·2020-02-20·CVSS 5.3
CVE-2020-10693 [MEDIUM] CVE-2020-10693 hibernate-validator: Improper input validation in the interpolation of constraint error messages
CVE-2020-10693 hibernate-validator: Improper input validation in the interpolation of constraint error messages
A flaw was found in hibernate-validator 6.1.2.Final. A bug in the interpolation of constraint error messages code enables invalid EL expressions to be evaluated as if they were valid. This bug enables attackers to bypass input sanitation (escaping, stripping) controls that developers may have put in place when handling user-controlled data in error messages.
Discussion:
Acknowledgments:
Name: Alvaro Muñoz (GitHub Security Labs)
---
Statement:
hibernate-validator is packaged with Red Hat OpenStack Platform 13.0's OpenDaylight (ODL). However, because ODL is technical preview in this version and the flaw is moderate, Red Hat will not be releasing a fix for the OpenStack packa
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-10693https://lists.apache.org/thread.html/rb8dca19a4e52b60dab0ab21e2ff9968d78f4b84e4033824db1dd24b4%40%3Cpluto-scm.portals.apache.org%3Ehttps://lists.apache.org/thread.html/rd418deda6f0ebe658c2015f43a14d03acb8b8c2c093c5bf6b880cd7c%40%3Cpluto-dev.portals.apache.org%3Ehttps://lists.apache.org/thread.html/rf9c17c3efc4a376a96e9e2777eee6acf0bec28e2200e4b35da62de4a%40%3Cpluto-dev.portals.apache.org%3Ehttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-10693https://lists.apache.org/thread.html/rb8dca19a4e52b60dab0ab21e2ff9968d78f4b84e4033824db1dd24b4%40%3Cpluto-scm.portals.apache.org%3Ehttps://lists.apache.org/thread.html/rd418deda6f0ebe658c2015f43a14d03acb8b8c2c093c5bf6b880cd7c%40%3Cpluto-dev.portals.apache.org%3Ehttps://lists.apache.org/thread.html/rf9c17c3efc4a376a96e9e2777eee6acf0bec28e2200e4b35da62de4a%40%3Cpluto-dev.portals.apache.org%3Ehttps://www.oracle.com/security-alerts/cpuapr2022.html
2020-05-06
Published