CVE-2023-1932: Hibernate-validator: rendering of invalid html with safehtml leads to html injection and xss

Published Mar 3, 2020
·
Updated

A flaw was found in hibernate-validator's 'isValid' method in the org.hibernate.validator.internal.constraintvalidators.hv.SafeHtmlValidator class, which can be bypassed by omitting the tag ending in a less-than character. Browsers may render an invalid html, allowing HTML injection or Cross-Site-Scripting (XSS) attacks.

Other sources

A vulnerability was found in hibernate-validator version 6.1.2.Final, where the method 'isValid' in the class org.hibernate.validator.internal.constraintvalidators.hv.SafeHtmlValidator can by bypassed by omitting the tag end (less than sign). Browsers typically still render the invalid html which leads to attacks like HTML injection and Cross-Site-Scripting.

Red Hat

Affected Software

9 affected componentsFixes available
maven/org.hibernate.validator:hibernate-validator<6.2.0.Final
6.2.0.Final
redhat Codeready Studio=12.0
redhat JBoss Enterprise Application Platform
redhat JBoss Enterprise Application Platform=7.0.0
redhat Openstack Platform=13.0
redhat Single Sign-on=7.0
Hibernate hibernate-validator<6.2
redhat/hibernate-validator<6.2
6.2
redhat/hibernate-validator<7.0
7.0

Event History

Mar 3, 2020
Data Sourced
via Red Hat·07:07 AM
DescriptionSeverityAffected Software
Nov 7, 2024
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
DescriptionSeverity
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
Affected Software
Advisory Published
via GitHub·12:30 PM

Frequently Asked Questions

1

What is the severity of CVE-2023-1932?

CVE-2023-1932 has been classified with a moderate severity due to the potential for HTML injection.

2

How do I fix CVE-2023-1932?

To fix CVE-2023-1932, update hibernate-validator to version 6.2.0.Final or later.

3

What causes CVE-2023-1932?

CVE-2023-1932 is caused by a flaw in the 'isValid' method of the SafeHtmlValidator class that allows for HTML injection.

4

Which applications are affected by CVE-2023-1932?

Applications using hibernate-validator versions up to 6.2.0.Final and specific Red Hat products such as JBoss and OpenStack are affected by CVE-2023-1932.

5

Is CVE-2023-1932 an external or internal vulnerability?

CVE-2023-1932 is an external vulnerability as it can be exploited through web browsers rendering HTML.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203