CVE-2019-10219

MEDIUM6.5EPSS 1.7%

The SafeHtml annotation in Hibernate-Validator does not properly guard against XSS attacks

Published: 1/8/2020Modified: 4/28/2026
Also known as:DEBIAN-CVE-2019-10219

Description

A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.

Affected packages (3)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM6.5CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

References (28)