CVE-2019-10219
בינונית 6.1
תיאור (מקור, אנגלית)
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
מדדים
- CVSS 3.1
-
6.1 (MEDIUM)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N - EPSS — סבירות ניצול
- 2% (אחוזון 100) נכון ל-17/9/2026
- CWE
- CWE-79
מוצרים מושפעים
redhat: hibernate validator; redhat: fuse; redhat: jboss data grid; redhat: jboss enterprise application platform; redhat: openshift application runtimes; redhat: single sign-on; redhat: enterprise linux; netapp: active iq unified manager; netapp: management services for element software and netapp hci; netapp: snapcenter plug-in; netapp: element; oracle: access manager; oracle: agile engineering data management; oracle: agile product lifecycle analytics; oracle: agile product lifecycle management
קישורים
- https://access.redhat.com/errata/RHSA-2020:0159 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0160 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0161 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0164 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0445 Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10219 Issue TrackingThird Party Advisory
- https://github.com/hibernate/hibernate-validator/commit/124b7dd6d9a4ad24d4d49f…
- https://github.com/hibernate/hibernate-validator/commit/20d729548511ac5cff6fd4…
- https://github.com/poc-effectiveness/PoCAdaptation/tree/main/Adapted/CVE-2019-…
- https://github.com/poc-effectiveness/PoCAdaptation/tree/main/Origin/CVE-2019-1…