101048vdb entry
http://www.securityfocus.com/bid/101048 CVE-2017-7536
HIGH
Privilege Escalation in Hibernate Validator
Record summary
CVE-2017-7536 has a selected CVSS score of 7.0 (high).
Description
In Hibernate Validator 5.2.x before 5.2.5 final, 5.3.x, and 5.4.x, it was found that when the security manager's reflective permissions, which allows it to access the private members of the class, are granted to Hibernate Validator, a potential privilege escalation can occur. By allowing the calling code to access those private members without the permission an attacker may be able to validate an invalid instance and access the private member value via ConstraintViolation#getInvalidValue().
Description source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
hibernate-validatorBrowse Red Hat, Inc. / hibernate-validator | CVE List | 5.2.x before 5.2.5 final | affected |
| 5.3.x | affected | ||
| 5.4.x | affected | ||
org.hibernate:hibernate-validatorBrowse Maven / org.hibernate:hibernate-validator | GitHub Advisory | 5.2.0 to < 5.2.5.Final · Fixed in 5.2.5.Final | affected |
| 5.3.0 to < 5.3.6.Final · Fixed in 5.3.6.Final | affected | ||
| 5.4.0 to < 5.4.2.Final · Fixed in 5.4.2.Final | affected |
References
Showing 12 of 241039744vdb entry
http://www.securitytracker.com/id/1039744 RHSA-2017:2808Vendor advisory
https://access.redhat.com/errata/RHSA-2017:2808 RHSA-2017:2809Vendor advisory
https://access.redhat.com/errata/RHSA-2017:2809 RHSA-2017:2810Vendor advisory
https://access.redhat.com/errata/RHSA-2017:2810 RHSA-2017:2811Vendor advisory
https://access.redhat.com/errata/RHSA-2017:2811 RHSA-2017:3141Vendor advisory
https://access.redhat.com/errata/RHSA-2017:3141 RHSA-2017:3454Vendor advisory
https://access.redhat.com/errata/RHSA-2017:3454 RHSA-2017:3455Vendor advisory
https://access.redhat.com/errata/RHSA-2017:3455 RHSA-2017:3456Vendor advisory
https://access.redhat.com/errata/RHSA-2017:3456 RHSA-2017:3458Vendor advisory
https://access.redhat.com/errata/RHSA-2017:3458 RHSA-2018:2740Vendor advisory
https://access.redhat.com/errata/RHSA-2018:2740