This repository has been archived by the owner on Jan 12, 2024. It is now read-only.
CVE-2019-10219 (Medium) detected in hibernate-validator-6.0.17.Final.jar - autoclosed #23
Labels
security vulnerability
Security vulnerability detected by WhiteSource
CVE-2019-10219 - Medium Severity Vulnerability
Vulnerable Library - hibernate-validator-6.0.17.Final.jar
Hibernate's Bean Validation (JSR-380) reference implementation.
Library home page: http://hibernate.org/validator
Path to dependency file: remote-device-client/pom.xml
Path to vulnerable library: /home/wss-scanner/.m2/repository/org/hibernate/validator/hibernate-validator/6.0.17.Final/hibernate-validator-6.0.17.Final.jar
Dependency Hierarchy:
Found in HEAD commit: 772c0e629e3808cf31104e97f73dbd1621b76476
Found in base branch: master
Vulnerability Details
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
Publish Date: 2019-11-08
URL: CVE-2019-10219
CVSS 3 Score Details (6.1)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-10219
Release Date: 2019-11-08
Fix Resolution: 6.0.18.Final
The text was updated successfully, but these errors were encountered: