REDHAT-BUG-1120495: Low severity red hat hibernate validator vulnerability
IssueDescription:
It was discovered that the implementation of org.hibernate.validator.util.ReflectionHelper together with the permissions required to run Hibernate Validator under the Java Security Manager could allow a malicious application deployed in the same application container to execute several actions with escalated privileges, which might otherwise not be possible. This flaw could be used to perform various attacks, including but not restricted to, arbitrary code execution in systems that are otherwise secured by the Java Security Manager.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1120495?
The vulnerability REDHAT-BUG-1120495 has been classified with a medium severity level.
How do I fix REDHAT-BUG-1120495?
To fix REDHAT-BUG-1120495, update Hibernate Validator to the latest recommended version that addresses this vulnerability.
What is affected by REDHAT-BUG-1120495?
REDHAT-BUG-1120495 affects applications utilizing Hibernate Validator in an environment with the Java Security Manager.
Is REDHAT-BUG-1120495 an exploit risk?
Yes, REDHAT-BUG-1120495 poses an exploit risk by allowing unauthorized code execution in specific configurations.
Who is responsible for addressing REDHAT-BUG-1120495?
Developers and system administrators using affected versions of Hibernate Validator should address REDHAT-BUG-1120495 promptly.