REDHAT-BUG-2370118: High severity Hibernate Hibernate Validator vulnerability
Hibernate Validator before 6.2.0 and 7.0.0, by default and depending how it is used, may interpolate user-supplied input in a constraint violation message with Expression Language. This could allow an attacker to access sensitive information or execute arbitrary Java code. Hibernate Validator as of 6.2.0 and 7.0.0 no longer interpolates custom constraint violation messages with Expression Language and strongly recommends not allowing user-supplied input in constraint violation messages. CVE-2020-5245 and CVE-2025-4428 are examples of related, downstream vulnerabilities involving Expression Language intepolation of user-supplied data.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2370118?
The severity of REDHAT-BUG-2370118 is considered high due to potential exploitation risks that could lead to exposing sensitive information or executing arbitrary Java code.
How do I fix REDHAT-BUG-2370118?
To fix REDHAT-BUG-2370118, upgrade Hibernate Validator to version 6.2.0 or later, or 7.0.0 or later.
What impact does REDHAT-BUG-2370118 have on applications?
REDHAT-BUG-2370118 can allow unauthorized access to sensitive data and introduce security vulnerabilities in applications using vulnerable versions.
Which versions are affected by REDHAT-BUG-2370118?
Versions of Hibernate Validator prior to 6.2.0 and 7.0.0 are affected by REDHAT-BUG-2370118.
Is user input safe in Hibernate Validator with REDHAT-BUG-2370118?
No, user input may be interpolated in constraint violation messages, which can create security risks with REDHAT-BUG-2370118.