PT-2014-5394 · Hibernate · Hibernate Validator
Publicado
2014-09-30
·
Atualizado
2022-05-14
·
CVE-2014-3558
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Hibernate Validator versions 4.1.0 through 4.2.1
Hibernate Validator versions 4.3.x through 4.3.2
Hibernate Validator versions 5.x through 5.1.2
Description
The issue allows attackers to bypass Java Security Manager restrictions and execute restricted reflection calls via a crafted application. This is related to the ReflectionHelper class in the org.hibernate.validator.util package.
Recommendations
For versions 4.1.0 through 4.2.1, update to version 4.2.1 or later.
For versions 4.3.x through 4.3.2, update to version 4.3.2 or later.
For versions 5.x through 5.1.2, update to version 5.1.2 or later.
Exploit
Correção
Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Hibernate Validator