A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
[
{
"signature_version": "v1",
"deprecated": false,
"source": "https://github.com/hibernate/hibernate-validator/commit/20d729548511ac5cff6fd459f93de137195420fe",
"signature_type": "Function",
"digest": {
"function_hash": "175043693980931391946325472196901261982",
"length": 316.0
},
"target": {
"file": "engine/src/main/java/org/hibernate/validator/internal/constraintvalidators/hv/SafeHtmlValidator.java",
"function": "getFragmentAsDocument"
},
"id": "CVE-2019-10219-5b89fcb2"
},
{
"signature_version": "v1",
"deprecated": false,
"source": "https://github.com/hibernate/hibernate-validator/commit/20d729548511ac5cff6fd459f93de137195420fe",
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"219734075697535224167509490062382763198",
"272235756869937729781175432290978856671",
"19237373970343524998363841477038877680"
]
},
"target": {
"file": "engine/src/test/java/org/hibernate/validator/test/internal/constraintvalidators/hv/SafeHtmlValidatorTest.java"
},
"id": "CVE-2019-10219-a0016ec7"
},
{
"signature_version": "v1",
"deprecated": false,
"source": "https://github.com/hibernate/hibernate-validator/commit/124b7dd6d9a4ad24d4d49f74701f05a13e56ceee",
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"219734075697535224167509490062382763198",
"272235756869937729781175432290978856671",
"19237373970343524998363841477038877680"
]
},
"target": {
"file": "engine/src/test/java/org/hibernate/validator/test/internal/constraintvalidators/hv/SafeHtmlValidatorTest.java"
},
"id": "CVE-2019-10219-a5349e36"
},
{
"signature_version": "v1",
"deprecated": false,
"source": "https://github.com/hibernate/hibernate-validator/commit/124b7dd6d9a4ad24d4d49f74701f05a13e56ceee",
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"94562007974873113223383557043872720899",
"112087544803190870516689888295945294808",
"306980318626675673733768057349926802933",
"296282881808670362458754500533165760262",
"130807650095190493876245857859802937574",
"112083924863206343392818469090430142738",
"194503736757800232895612025996828768976",
"311316402218926050600670133194639076070",
"331227458559397502816808246571490931361",
"336226852424949880660456654843462642296",
"208244545094952328228448506877135837577",
"105705860365403714807158576657335853075"
]
},
"target": {
"file": "engine/src/main/java/org/hibernate/validator/internal/constraintvalidators/hv/SafeHtmlValidator.java"
},
"id": "CVE-2019-10219-cc8f641a"
},
{
"signature_version": "v1",
"deprecated": false,
"source": "https://github.com/hibernate/hibernate-validator/commit/124b7dd6d9a4ad24d4d49f74701f05a13e56ceee",
"signature_type": "Function",
"digest": {
"function_hash": "175043693980931391946325472196901261982",
"length": 316.0
},
"target": {
"file": "engine/src/main/java/org/hibernate/validator/internal/constraintvalidators/hv/SafeHtmlValidator.java",
"function": "getFragmentAsDocument"
},
"id": "CVE-2019-10219-d43e5655"
},
{
"signature_version": "v1",
"deprecated": false,
"source": "https://github.com/hibernate/hibernate-validator/commit/20d729548511ac5cff6fd459f93de137195420fe",
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"94562007974873113223383557043872720899",
"112087544803190870516689888295945294808",
"306980318626675673733768057349926802933",
"296282881808670362458754500533165760262",
"130807650095190493876245857859802937574",
"112083924863206343392818469090430142738",
"194503736757800232895612025996828768976",
"311316402218926050600670133194639076070",
"331227458559397502816808246571490931361",
"336226852424949880660456654843462642296",
"208244545094952328228448506877135837577",
"105705860365403714807158576657335853075"
]
},
"target": {
"file": "engine/src/main/java/org/hibernate/validator/internal/constraintvalidators/hv/SafeHtmlValidator.java"
},
"id": "CVE-2019-10219-dddf6471"
}
]