CVE-2020-10693 MEDIUM

CVE-2020-10693

Vendor Hibernate
Product hibernate-validator
Weakness CWE-20 · Input validation
Published May 6, 2020
Last update August 4, 2024

CVSS base score

5.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

What the vulnerability does

01Description

A flaw was found in Hibernate Validator version 6.1.2.Final. A bug in the message interpolation processor enables invalid EL expressions to be evaluated as if they were valid. This flaw allows attackers to bypass input sanitation (escaping, stripping) controls that developers may have put in place when handling user-controlled data in error messages.

Key dates

02Disclosure timeline

May 6, 2020 CVE published
August 4, 2024 Record updated