CVE-2019-10219
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
- Affected products
- Alt Linux, Debian, Hibernate Validator, Red Os, Virtualbox
- Redhat Hibernate Validator
- < 6.0.18, 6.1.0
- CVSS 3.0
- 6.5 MEDIUM
- EPSS
- 2.2% (81th percentile)
- Weakness
- CWE-79
- NVD status
- Modified
- Published
- 2019-11-08
CVE-2019-10219 at NVD
2 known exploits for CVE-2019-10219
Proof-of-concept code and exploit modules indexed by Sploitus