PT-2014-5394 · Hibernate · Hibernate Validator

Published

2014-09-30

·

Updated

2022-05-14

·

CVE-2014-3558

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Hibernate Validator versions 4.1.0 through 4.2.1 Hibernate Validator versions 4.3.x through 4.3.2 Hibernate Validator versions 5.x through 5.1.2
Description The issue allows attackers to bypass Java Security Manager restrictions and execute restricted reflection calls via a crafted application. This is related to the ReflectionHelper class in the org.hibernate.validator.util package.
Recommendations For versions 4.1.0 through 4.2.1, update to version 4.2.1 or later. For versions 4.3.x through 4.3.2, update to version 4.3.2 or later. For versions 5.x through 5.1.2, update to version 5.1.2 or later.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-3558
GHSA-845H-985R-JRQH
RHSA-2014:1285
RHSA-2014:1286
RHSA-2014:1287

Affected Products

Hibernate Validator