SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-10219

A vulnerability was found in Hibernate-Validator.

MEDIUM 6.1EPSS 2.17%

Does this matter?

Lower severity and a low EPSS score (2.17%). Track it; it rarely justifies an emergency change on its own.

Description

A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.

CVSS 3.1
6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS
2.17% probability · 81th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
redhat/hibernate validator · redhat/fuse · redhat/jboss data grid · redhat/jboss enterprise application platform · redhat/openshift application runtimes · redhat/single sign-on · netapp/active iq unified manager · netapp/management services for element software and netapp hci · netapp/snapcenter plug-in · netapp/element · oracle/access manager · oracle/agile engineering data management · oracle/agile product lifecycle analytics · oracle/agile product lifecycle management · oracle/agile product lifecycle management integration pack · oracle/airlines data model · oracle/application express · oracle/application performance management · oracle/application testing suite · oracle/argus analytics · +40 more
Source
secalert@redhat.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.