A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
CVSS Details
- CVSS 3.1 Base Score: 6.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
- CVSS 3.0 Base Score: 6.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | No solution exists | May 15, 2025 | Nov 8, 2019 |
| Oracle Virtualbox | — | Upgrade Oracle VirtualBox to the latest version | Jul 17, 2025 | Nov 8, 2019 |
| Oracle Weblogic | — | Apply the Patch Set Update (PSU) 33727619 for version 14.1.1.0.0.Apply the Patch Set Update (PSU) 33699205 for version 12.2.1.3.0.Apply the Patch Set Update (PSU) 33727616 for version 12.2.1.4.0. | Feb 28, 2022 | Nov 8, 2019 |
| Red Hat Jboss Eap | — | Upgrade Red Hat JBoss EAP to the latest version | Sep 19, 2024 | Aug 28, 2019 |
| Red_hat Jboss_eap | — | — | Apr 10, 2023 | Nov 8, 2019 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Nov 8, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub