CVE-2023-1932
Hibernate-validator: rendering of invalid html with safehtml leads to html injection and xss
A flaw was found in hibernate-validator's 'isValid' method in the org.hibernate.validator.internal.constraintvalidators.hv.SafeHtmlValidator class, which can be bypassed by omitting the tag ending in a less-than character. Browsers may render an invalid html, allowing HTML injection or Cross-Site-Scripting (XSS) attacks.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Produtos afetados
Red Hat · A-MQ Clients 2Red Hat · Cryostat 2Red Hat · Red Hat AMQ Broker 7Red Hat · Red Hat A-MQ OnlineRed Hat · Red Hat BPM Suite 6Red Hat · Red Hat CodeReady Studio 12Red Hat · Red Hat Data Grid 8Red Hat · Red Hat Decision Manager 7Red Hat · Red Hat Fuse 7Red Hat · Red Hat JBoss BRMS 5Red Hat · Red Hat JBoss Data Grid 7Red Hat · Red Hat JBoss Data Virtualization 6Red Hat · Red Hat JBoss Enterprise Application Platform 5Red Hat · Red Hat JBoss Enterprise Application Platform 6Red Hat · Red Hat JBoss Enterprise Application Platform 7Red Hat · Red Hat JBoss Enterprise Application Platform Continuous DeliveryRed Hat · Red Hat JBoss Fuse 6Red Hat · Red Hat JBoss Fuse Service Works 6Red Hat · Red Hat JBoss Operations Network 3Red Hat · Red Hat JBoss SOA Platform 5Red Hat · Red Hat OpenStack Platform 10 (Newton)Red Hat · Red Hat OpenStack Platform 13 (Queens)Red Hat · Red Hat Process Automation 7Red Hat · Red Hat Satellite 6Red Hat · Red Hat Single Sign-On 7Red Hat · Red Hat support for Spring BootRed Hat · streams for Apache KafkaQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →