PT-2014-5394 · Hibernate · Hibernate Validator
Published
2014-09-30
·
Updated
2022-05-14
·
CVE-2014-3558
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Hibernate Validator versions 4.1.0 through 4.2.1
Hibernate Validator versions 4.3.x through 4.3.2
Hibernate Validator versions 5.x through 5.1.2
Description
The issue allows attackers to bypass Java Security Manager restrictions and execute restricted reflection calls via a crafted application. This is related to the ReflectionHelper class in the org.hibernate.validator.util package.
Recommendations
For versions 4.1.0 through 4.2.1, update to version 4.2.1 or later.
For versions 4.3.x through 4.3.2, update to version 4.3.2 or later.
For versions 5.x through 5.1.2, update to version 5.1.2 or later.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hibernate Validator