Miggo Logo

CVE-2019-10219: The SafeHtml annotation in Hibernate-Validator does not properly guard against XSS attacks

6.5

CVSS Score
3.0

Basic Information

EPSS Score
0.82245%
Published
1/8/2020
Updated
5/15/2024
KEV Status
No
Technology
TechnologyJava

Technical Details

CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Package NameEcosystemVulnerable VersionsFirst Patched Version
org.hibernate.validator:hibernate-validatormaven>= 6.1.0.Alpha1, < 6.1.0.Alpha66.1.0.Alpha6

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis:
In progress

WAF Protection Rules

WAF Rule

* vuln*r**ility w*s *oun* in *i**rn*t*-V*li**tor. T** S****tml v*li**tor *nnot*tion **ils to prop*rly s*nitiz* p*ylo**s *onsistin* o* pot*nti*lly m*li*ious *o** in *TML *omm*nts *n* instru*tions. T*is vuln*r**ility **n r*sult in *n XSS *tt**k.

Reasoning

No *n*lysis *v*il**l*