CVE-2019-10219

MEDIUM6.5EPSS 1.7%

The SafeHtml annotation in Hibernate-Validator does not properly guard against XSS attacks

發布日:2020/1/8修改日:2026/4/28

描述

A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.

受影響套件(3)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1MEDIUM6.5CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

參考連結(28)