The SafeHtml annotation in Hibernate-Validator does not properly guard against XSS attacks
Moderate severity
GitHub Reviewed
Published
Jan 8, 2020
to the GitHub Advisory Database
•
Updated May 15, 2024
Package
Affected versions
>= 6.1.0.Alpha1, < 6.1.0.Alpha6
Patched versions
6.1.0.Alpha6
Description
Published by the National Vulnerability Database
Nov 8, 2019
Reviewed
Jan 8, 2020
Published to the GitHub Advisory Database
Jan 8, 2020
Last updated
May 15, 2024
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
References