Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2023-1932— Hibernate-validator: rendering of invalid html with safehtml leads to html injection and xss

CVSS 6.1 · Medium EPSS 0.85% · P75
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2023-1932

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Hibernate-validator: rendering of invalid html with safehtml leads to html injection and xss
Source: NVD (National Vulnerability Database)
Vulnerability Description
A flaw was found in hibernate-validator's 'isValid' method in the org.hibernate.validator.internal.constraintvalidators.hv.SafeHtmlValidator class, which can be bypassed by omitting the tag ending in a less-than character. Browsers may render an invalid html, allowing HTML injection or Cross-Site-Scripting (XSS) attacks.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Hibernate Validator 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Hibernate Validator是一款参数校验框架。 Hibernate Validator存在安全漏洞,该漏洞源于浏览器可能会呈现无效的html。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
Red HatA-MQ Clients 2-cpe:/a:redhat:a_mq_clients:2
Red HatCryostat 2-cpe:/a:redhat:cryostat:2
Red HatRed Hat AMQ Broker 7-cpe:/a:redhat:amq_broker:7
Red HatRed Hat A-MQ Online-cpe:/a:redhat:amq_online:1
Red HatRed Hat BPM Suite 6-cpe:/a:redhat:jboss_enterprise_bpms_platform:6
Red HatRed Hat CodeReady Studio 12-cpe:/a:redhat:jboss_developer_studio:12.
Red HatRed Hat Data Grid 8-cpe:/a:redhat:jboss_data_grid:8
Red HatRed Hat Decision Manager 7-cpe:/a:redhat:jboss_enterprise_brms_platform:7
Red HatRed Hat Fuse 7-cpe:/a:redhat:jboss_fuse:7
Red HatRed Hat JBoss BRMS 5-cpe:/a:redhat:jboss_enterprise_brms_platform:5
Red HatRed Hat JBoss Data Grid 7-cpe:/a:redhat:jboss_data_grid:7
Red HatRed Hat JBoss Data Virtualization 6-cpe:/a:redhat:jboss_data_virtualization:6
Red HatRed Hat JBoss Enterprise Application Platform 5-cpe:/a:redhat:jboss_enterprise_application_platform:5
Red HatRed Hat JBoss Enterprise Application Platform 6-cpe:/a:redhat:jboss_enterprise_application_platform:6
Red HatRed Hat JBoss Enterprise Application Platform 7-cpe:/a:redhat:jboss_enterprise_application_platform:7
Red HatRed Hat JBoss Enterprise Application Platform Continuous Delivery-cpe:/a:redhat:jboss_enterprise_application_platform_cd
Red HatRed Hat JBoss Fuse 6-cpe:/a:redhat:jboss_fuse:6
Red HatRed Hat JBoss Fuse Service Works 6-cpe:/a:redhat:jboss_fuse_service_works:6
Red HatRed Hat JBoss Operations Network 3-cpe:/a:redhat:jboss_operations_network:3
Red HatRed Hat JBoss SOA Platform 5-cpe:/a:redhat:jboss_enterprise_soa_platform:5
Red HatRed Hat OpenStack Platform 10 (Newton)-cpe:/a:redhat:openstack:10
Red HatRed Hat OpenStack Platform 13 (Queens)-cpe:/a:redhat:openstack:13
Red HatRed Hat Process Automation 7-cpe:/a:redhat:jboss_enterprise_bpms_platform:7
Red HatRed Hat Satellite 6-cpe:/a:redhat:satellite:6
Red HatRed Hat Single Sign-On 7-cpe:/a:redhat:red_hat_single_sign_on:7
Red HatRed Hat support for Spring Boot-cpe:/a:redhat:openshift_application_runtimes:1.0
Red Hatstreams for Apache Kafka-cpe:/a:redhat:amq_streams:1

II. Public POCs for CVE-2023-1932

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2023-1932

登录查看更多情报信息。

IV. Related Vulnerabilities

V. Comments for CVE-2023-1932

No comments yet


Leave a comment