PT-2014-5394 · Hibernate · Hibernate Validator

Publicado

2014-09-30

·

Atualizado

2022-05-14

·

CVE-2014-3558

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Hibernate Validator versions 4.1.0 through 4.2.1 Hibernate Validator versions 4.3.x through 4.3.2 Hibernate Validator versions 5.x through 5.1.2
Description The issue allows attackers to bypass Java Security Manager restrictions and execute restricted reflection calls via a crafted application. This is related to the ReflectionHelper class in the org.hibernate.validator.util package.
Recommendations For versions 4.1.0 through 4.2.1, update to version 4.2.1 or later. For versions 4.3.x through 4.3.2, update to version 4.3.2 or later. For versions 5.x through 5.1.2, update to version 5.1.2 or later.

Exploit

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-3558
GHSA-845H-985R-JRQH
RHSA-2014:1285
RHSA-2014:1286
RHSA-2014:1287

Produtos afetados

Hibernate Validator