CVE-2023-1932
published 2024-11-07CVE-2023-1932: A flaw was found in hibernate-validator's 'isValid' method in the org.hibernate.validator.internal.constraintvalidators.hv.SafeHtmlValidator class, which can…
PriorityP425medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
0.45%
36.6th percentile
A flaw was found in hibernate-validator's 'isValid' method in the org.hibernate.validator.internal.constraintvalidators.hv.SafeHtmlValidator class, which can be bypassed by omitting the tag ending in a less-than character. Browsers may render an invalid html, allowing HTML injection or Cross-Site-Scripting (XSS) attacks.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libhibernate-validator-java | — | — |
| hibernate | hibernate-validator | < 6.2 | 6.2 |
| redhat | codeready_studio | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | openstack_platform | — | — |
| redhat | single_sign-on | — | — |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
osv6.1MEDIUM
vendor_debian6.1MEDIUM
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
hibernate-validator Cross-site Scripting vulnerability
osv·2024-11-07
CVE-2023-1932 [MEDIUM] hibernate-validator Cross-site Scripting vulnerability
hibernate-validator Cross-site Scripting vulnerability
A flaw was found in hibernate-validator's 'isValid' method in the org.hibernate.validator.internal.constraintvalidators.hv.SafeHtmlValidator class, which can be bypassed by omitting the tag ending in a less-than character. Browsers may render an invalid html, allowing HTML injection or Cross-Site-Scripting (XSS) attacks.
GHSA
hibernate-validator Cross-site Scripting vulnerability
ghsa·2024-11-07
CVE-2023-1932 [MEDIUM] CWE-79 hibernate-validator Cross-site Scripting vulnerability
hibernate-validator Cross-site Scripting vulnerability
A flaw was found in hibernate-validator's 'isValid' method in the org.hibernate.validator.internal.constraintvalidators.hv.SafeHtmlValidator class, which can be bypassed by omitting the tag ending in a less-than character. Browsers may render an invalid html, allowing HTML injection or Cross-Site-Scripting (XSS) attacks.
OSV
CVE-2023-1932: A flaw was found in hibernate-validator's 'isValid' method in the org
osv·2024-11-07·CVSS 6.1
CVE-2023-1932 [MEDIUM] CVE-2023-1932: A flaw was found in hibernate-validator's 'isValid' method in the org
A flaw was found in hibernate-validator's 'isValid' method in the org.hibernate.validator.internal.constraintvalidators.hv.SafeHtmlValidator class, which can be bypassed by omitting the tag ending in a less-than character. Browsers may render an invalid html, allowing HTML injection or Cross-Site-Scripting (XSS) attacks.
Red Hat
hibernate-validator: rendering of invalid html with SafeHTML leads to HTML injection and XSS
vendor_redhat·2024-02-07·CVSS 6.1
CVE-2023-1932 [MEDIUM] CWE-1286 hibernate-validator: rendering of invalid html with SafeHTML leads to HTML injection and XSS
hibernate-validator: rendering of invalid html with SafeHTML leads to HTML injection and XSS
A flaw was found in hibernate-validator's 'isValid' method in the org.hibernate.validator.internal.constraintvalidators.hv.SafeHtmlValidator class, which can be bypassed by omitting the tag ending in a less-than character. Browsers may render an invalid html, allowing HTML injection or Cross-Site-Scripting (XSS) attacks.
A flaw was found in hibernate-validator's 'isValid' method in the org.hibernate.validator.internal.constraintvalidators.hv.SafeHtmlValidator class, which can be bypassed by omitting the tag ending in a less-than character. Browsers may render an invalid html, allowing HTML injection or Cross-Site-Scripting (XSS) attacks.
Statement: Hibernate-validator is packaged with Red Hat Op
Debian
CVE-2023-1932: libhibernate-validator-java - A flaw was found in hibernate-validator's 'isValid' method in the org.hibernate....
vendor_debian·2023·CVSS 6.1
CVE-2023-1932 [MEDIUM] CVE-2023-1932: libhibernate-validator-java - A flaw was found in hibernate-validator's 'isValid' method in the org.hibernate....
A flaw was found in hibernate-validator's 'isValid' method in the org.hibernate.validator.internal.constraintvalidators.hv.SafeHtmlValidator class, which can be bypassed by omitting the tag ending in a less-than character. Browsers may render an invalid html, allowing HTML injection or Cross-Site-Scripting (XSS) attacks.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2023-54202 kernel: drm/i915: fix race condition UAF in i915_perf_add_config_ioctl
bugzilla·2025-12-30
CVE-2023-54202 [LOW] CVE-2023-54202 kernel: drm/i915: fix race condition UAF in i915_perf_add_config_ioctl
CVE-2023-54202 kernel: drm/i915: fix race condition UAF in i915_perf_add_config_ioctl
In the Linux kernel, the following vulnerability has been resolved:
drm/i915: fix race condition UAF in i915_perf_add_config_ioctl
Userspace can guess the id value and try to race oa_config object creation
with config remove, resulting in a use-after-free if we dereference the
object after unlocking the metrics_lock. For that reason, unlocking the
metrics_lock must be done after we are done dereferencing the object.
[tursulin: Manually added stable tag.]
(cherry picked from commit 49f6f6483b652108bcb73accd0204a464b922395)
Discussion:
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2025123031-CVE-2023-54202-1932@gregkh/T
Bugzilla
CVE-2023-1932 hibernate-validator: rendering of invalid html with SafeHTML leads to HTML injection and XSS
bugzilla·2020-03-03·CVSS 6.1
CVE-2023-1932 [MEDIUM] CVE-2023-1932 hibernate-validator: rendering of invalid html with SafeHTML leads to HTML injection and XSS
CVE-2023-1932 hibernate-validator: rendering of invalid html with SafeHTML leads to HTML injection and XSS
A vulnerability was found in hibernate-validator version 6.1.2.Final, where the method 'isValid' in the class org.hibernate.validator.internal.constraintvalidators.hv.SafeHtmlValidator can by bypassed by omitting the tag end (less than sign). Browsers typically still render the invalid html which leads to attacks like HTML injection and Cross-Site-Scripting.
Discussion:
Statement:
hibernate-validator is packaged with Red Hat OpenStack Platform 13.0's OpenDaylight (ODL). However, because ODL is technical preview in this version and the flaw is moderate, Red Hat will not be releasing a fix for the OpenStack package at this time.
Supported versions of Satellite 6 embed vulnerable ve
2024-11-07
Published