Remote command execution In org.hibernate:hibernate-validator
Description
Privilege Escalation in Hibernate Validator In Hibernate Validator 5.2.x before 5.2.5.Final, 5.3.x before 5.3.6.Final, and 5.4.x before 5.4.2.Final, it was found that when the security manager's reflective permissions, which allows it to access the private members of the class, are granted to Hibernate Validator, a potential privilege escalation can occur. By allowing the calling code to access those private members without the permission an attacker may be able to validate an invalid instance and access the private member value via ConstraintViolation#getInvalidValue().
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
maven | 5.2.5.final, 5.3.6.final, 5.4.2.final | ||
debian 14 | 4.3.3-4 | ||
debian 12 | 4.3.3-4 | ||
debian 11 | 4.3.3-4 | ||
debian 13 | 4.3.3-4 |
Aliases
References