CVE-2020-10693
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD
Description
A flaw was found in Hibernate Validator version 6.1.2.Final. A bug in the message interpolation processor enables invalid EL expressions to be evaluated as if they were valid. This flaw allows attackers to bypass input sanitation (escaping, stripping) controls that developers may have put in place when handling user-controlled data in error messages.
Affected (10)
Products: Redhat: Hibernate Validator, Jboss Enterprise Application Platform, Satellite, Satellite Capsule · Ibm: Websphere Application Server · Quarkus: Quarkus · +1 more
Show all products
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 5.0.0 to 6.0.20 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| From 17.0.0.3 to 20.0.0.10 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 7.2.0 |
| Running on/with | Platform Versions |
|---|---|
Redhat Enterprise Linux | Version 6.0 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 6.8 | |
| Version 6.8 |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Version 14.1.1.0.0 |
References (10)
Source: secalert@redhat.com
Issue TrackingThird Party Advisory
Source: secalert@redhat.com
Source: secalert@redhat.com
Source: secalert@redhat.com
Source: secalert@redhat.com
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Timeline
No history available yet.