Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-1932


A flaw was found in hibernate-validator's 'isValid' method in the org.hibernate.validator.internal.constraintvalidators.hv.SafeHtmlValidator class, which can be bypassed by omitting the tag ending in a less-than character. Browsers may render an invalid html, allowing HTML injection or Cross-Site-Scripting (XSS) attacks.


Published

2024-11-07T10:15:04.507

Last Modified

2025-06-24T13:07:42.087

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 6.1 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application redhat codeready_studio 12.0 Yes
Application redhat jboss_enterprise_application_platform - Yes
Application redhat jboss_enterprise_application_platform 7.0.0 Yes
Application redhat openstack_platform 13.0 Yes
Application redhat single_sign-on 7.0 Yes
Application hibernate hibernate-validator < 6.2 Yes

References