Medium severity6.1NVD Advisory· Published Nov 7, 2024· Updated Jun 17, 2026
CVE-2023-1932
CVE-2023-1932
Description
A flaw was found in hibernate-validator's 'isValid' method in the org.hibernate.validator.internal.constraintvalidators.hv.SafeHtmlValidator class, which can be bypassed by omitting the tag ending in a less-than character. Browsers may render an invalid html, allowing HTML injection or Cross-Site-Scripting (XSS) attacks.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.hibernate.validator:hibernate-validatorMaven | < 6.2.0.Final | 6.2.0.Final |
org.hibernate:hibernate-validatorMaven | < 6.2.0.Final | 6.2.0.Final |
Affected products
35- Red Hat/A-MQ Clients 2v5cpe:/a:redhat:a_mq_clients:2
- Red Hat/Red Hat AMQ Broker 7v5cpe:/a:redhat:amq_broker:7
- cpe:/a:redhat:amq_online:1
- Red Hat/streams for Apache Kafkav5cpe:/a:redhat:amq_streams:1
- Red Hat/Red Hat JBoss Data Grid 7v5cpe:/a:redhat:jboss_data_grid:7
- Red Hat/Red Hat Data Grid 8v5cpe:/a:redhat:jboss_data_grid:8
- cpe:/a:redhat:jboss_data_virtualization:6
cpe:/a:redhat:jboss_developer_studio:12.+ 1 more
- cpe:/a:redhat:jboss_developer_studio:12.
- cpe:2.3:a:redhat:codeready_studio:12.0:*:*:*:*:*:*:*
cpe:/a:redhat:jboss_enterprise_application_platform:5+ 5 more
- cpe:/a:redhat:jboss_enterprise_application_platform:5
- cpe:/a:redhat:jboss_enterprise_application_platform:6
- cpe:/a:redhat:jboss_enterprise_application_platform:7
- cpe:/a:redhat:jboss_enterprise_application_platform_cd
- cpe:2.3:a:redhat:jboss_enterprise_application_platform:-:*:*:*:continuous_delivery:*:*:*
- cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.0.0:*:*:*:*:*:*:*
- cpe:/a:redhat:jboss_enterprise_bpms_platform:6
- cpe:/a:redhat:jboss_enterprise_bpms_platform:7
- cpe:/a:redhat:jboss_enterprise_brms_platform:5
- cpe:/a:redhat:jboss_enterprise_brms_platform:7
- cpe:/a:redhat:jboss_enterprise_soa_platform:5
- Red Hat/Red Hat JBoss Fuse 6v5cpe:/a:redhat:jboss_fuse:6
- Red Hat/Red Hat Fuse 7v5cpe:/a:redhat:jboss_fuse:7
- cpe:/a:redhat:jboss_fuse_service_works:6
- cpe:/a:redhat:jboss_operations_network:3
- cpe:/a:redhat:openshift_application_runtimes:1.0
cpe:/a:redhat:red_hat_single_sign_on:7+ 1 more
- cpe:/a:redhat:red_hat_single_sign_on:7
- cpe:2.3:a:redhat:single_sign-on:7.0:*:*:*:*:*:*:*
- ghsa-coords2 versions
< 6.2.0.Final+ 1 more
- (no CPE)range: < 6.2.0.Final
- (no CPE)range: < 6.2.0.Final
Patches
Vulnerability mechanics
References
4- access.redhat.com/security/cve/CVE-2023-1932nvdVendor AdvisoryWEB
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingVendor AdvisoryWEB
- github.com/advisories/GHSA-x83m-pf6f-pf9gghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-1932ghsaADVISORY
News mentions
0No linked articles in our index yet.