Back

MEDIUM

hibernate-validator: safeHTML validator allows XSS

Published Nov 8, 2019

Description

A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.

Affected products

Remediation

Red Hat statement

Red Hat OpenStack Platform's OpenDaylight will not be updated for this flaw because it is being deprecated and is only receiving security fixes for Important and Critical flaws.

Metrics

References (30)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Nov 8, 2019
Updated Jul 7, 2025
Reserved Mar 27, 2019
NVD
Status Modified
Modified Aug 25, 2026
Red Hat
Severity Moderate
Public date Aug 28, 2019
GHSA-M8P2-495H-CCMH