Hibernate Hibernate-Validator vulnerabilities

3 known vulnerabilities affecting hibernate/hibernate-validator.

Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM3

Vulnerabilities

Page 1 of 1
CVE-2023-1932MEDIUMCVSS 6.1fixed in 6.22024-11-07
CVE-2023-1932 [MEDIUM] CWE-79 CVE-2023-1932: A flaw was found in hibernate-validator's 'isValid' method in the org.hibernate.validator.internal.c A flaw was found in hibernate-validator's 'isValid' method in the org.hibernate.validator.internal.constraintvalidators.hv.SafeHtmlValidator class, which can be bypassed by omitting the tag ending in a less-than character. Browsers may render an invalid html, allowing HTML injection or Cross-Site-Scripting (XSS) attacks.
nvd
CVE-2020-10693MEDIUMCVSS 5.3v6.1.2.Final2020-05-06
CVE-2020-10693 [MEDIUM] CWE-20 CVE-2020-10693: A flaw was found in Hibernate Validator version 6.1.2.Final. A bug in the message interpolation proc A flaw was found in Hibernate Validator version 6.1.2.Final. A bug in the message interpolation processor enables invalid EL expressions to be evaluated as if they were valid. This flaw allows attackers to bypass input sanitation (escaping, stripping) controls that developers may have put in place when handling user-controlled data in error messages.
cvelistv5nvd
CVE-2019-10219MEDIUMCVSS 6.1≥ 6.0.0.Alpha1, ≤ 6.0.17.Final≥ 6.1.0.Alpha1, ≤ 6.1.0.Alpha62019-11-08
CVE-2019-10219 [MEDIUM] CWE-79 CVE-2019-10219: A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properl A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
cvelistv5nvd