Back

HIGH

hibernate-validator: Privilege escalation when running under the security manager

Published Jan 10, 2018

Description

In Hibernate Validator 5.2.x before 5.2.5 final, 5.3.x, and 5.4.x, it was found that when the security manager's reflective permissions, which allows it to access the private members of the class, are granted to Hibernate Validator, a potential privilege escalation can occur. By allowing the calling code to access those private members without the permission an attacker may be able to validate an invalid instance and access the private member value via ConstraintViolation#getInvalidValue().

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (2)

References (26)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jan 10, 2018
Updated Sep 16, 2024
Reserved Apr 5, 2017
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Sep 26, 2017
GHSA-XXGP-PCFC-3VGC