VYPR
Medium severity6.1NVD Advisory· Published Nov 7, 2024· Updated Jun 17, 2026

CVE-2023-1932

CVE-2023-1932

Description

A flaw was found in hibernate-validator's 'isValid' method in the org.hibernate.validator.internal.constraintvalidators.hv.SafeHtmlValidator class, which can be bypassed by omitting the tag ending in a less-than character. Browsers may render an invalid html, allowing HTML injection or Cross-Site-Scripting (XSS) attacks.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.hibernate.validator:hibernate-validatorMaven
< 6.2.0.Final6.2.0.Final
org.hibernate:hibernate-validatorMaven
< 6.2.0.Final6.2.0.Final

Affected products

35
  • Red Hat/A-MQ Clients 2v5
    cpe:/a:redhat:a_mq_clients:2
  • Red Hat/Red Hat AMQ Broker 7v5
    cpe:/a:redhat:amq_broker:7
  • cpe:/a:redhat:amq_online:1
  • Red Hat/streams for Apache Kafkav5
    cpe:/a:redhat:amq_streams:1
  • Red Hat/Cryostatcpe-rescue
    cpe:/a:redhat:cryostat:2
  • Red Hat/Red Hat JBoss Data Grid 7v5
    cpe:/a:redhat:jboss_data_grid:7
  • Red Hat/Red Hat Data Grid 8v5
    cpe:/a:redhat:jboss_data_grid:8
  • cpe:/a:redhat:jboss_data_virtualization:6
  • Red Hat/Codeready Studiocpe-rescue2 versions
    cpe:/a:redhat:jboss_developer_studio:12.+ 1 more
    • cpe:/a:redhat:jboss_developer_studio:12.
    • cpe:2.3:a:redhat:codeready_studio:12.0:*:*:*:*:*:*:*
  • cpe:/a:redhat:jboss_enterprise_application_platform:5+ 5 more
    • cpe:/a:redhat:jboss_enterprise_application_platform:5
    • cpe:/a:redhat:jboss_enterprise_application_platform:6
    • cpe:/a:redhat:jboss_enterprise_application_platform:7
    • cpe:/a:redhat:jboss_enterprise_application_platform_cd
    • cpe:2.3:a:redhat:jboss_enterprise_application_platform:-:*:*:*:continuous_delivery:*:*:*
    • cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.0.0:*:*:*:*:*:*:*
  • cpe:/a:redhat:jboss_enterprise_bpms_platform:6
  • cpe:/a:redhat:jboss_enterprise_bpms_platform:7
  • cpe:/a:redhat:jboss_enterprise_brms_platform:5
  • cpe:/a:redhat:jboss_enterprise_brms_platform:7
  • cpe:/a:redhat:jboss_enterprise_soa_platform:5
  • Red Hat/Red Hat JBoss Fuse 6v5
    cpe:/a:redhat:jboss_fuse:6
  • Red Hat/Red Hat Fuse 7v5
    cpe:/a:redhat:jboss_fuse:7
  • cpe:/a:redhat:jboss_fuse_service_works:6
  • cpe:/a:redhat:jboss_operations_network:3
  • cpe:/a:redhat:openshift_application_runtimes:1.0
  • Red Hat/Openstackcpe-rescue3 versions
    cpe:/a:redhat:openstack:10+ 2 more
    • cpe:/a:redhat:openstack:10
    • cpe:/a:redhat:openstack:13
    • cpe:2.3:a:redhat:openstack_platform:13.0:*:*:*:*:*:*:*
  • Red Hat/Single Sign Oncpe-rescue2 versions
    cpe:/a:redhat:red_hat_single_sign_on:7+ 1 more
    • cpe:/a:redhat:red_hat_single_sign_on:7
    • cpe:2.3:a:redhat:single_sign-on:7.0:*:*:*:*:*:*:*
  • Red Hat/Satellitecpe-rescue
    cpe:/a:redhat:satellite:6
  • cpe:2.3:a:hibernate:hibernate-validator:*:*:*:*:*:*:*:*
    Range: <6.2
  • ghsa-coords2 versions
    < 6.2.0.Final+ 1 more
    • (no CPE)range: < 6.2.0.Final
    • (no CPE)range: < 6.2.0.Final

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.