ZeroHour

CVE-2019-10219

CVSS 3.1
6.1 medium
EPSS
2%p81
Published
()
Modified
Description

A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.

Vendors
redhatnetapporacle
Products
hibernate validator, fuse, jboss data grid, jboss enterprise application platform, openshift application runtimes, single sign-on, active iq unified manager, management services for element software and netapp hci, snapcenter plug-in, element, access manager, agile engineering data management
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.