Cross-Site Scripting (XSS) Affecting org.hibernate.validator:hibernate-validator package, versions [,6.2.0)


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.04% (12th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Cross-Site Scripting (XSS) vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-JAVA-ORGHIBERNATEVALIDATOR-6247635
  • published15 Feb 2024
  • disclosed7 Feb 2024
  • creditChristian Kistner, Moritz Bechler

Introduced: 7 Feb 2024

CVE-2023-1932  (opens in a new tab)
CWE-79  (opens in a new tab)

How to fix?

Upgrade org.hibernate.validator:hibernate-validator to version 6.2.0 or higher.

Overview

org.hibernate.validator:hibernate-validator is a Hibernate Validator Engine Relocation Artifact.

Affected versions of this package are vulnerable to Cross-Site Scripting (XSS) due to the isValid method in the org.hibernate.validator.internal.constraintvalidators.hv.SafeHtmlValidator class, which can be bypassed by omitting the tag ending in a less-than character. Browsers may render invalid HTML, allowing for the injection of arbitrary HTML content or the execution of scripts in the context of the user's browser session by crafting malicious input.

CVSS Scores

version 3.1