Input Validation Flaw in Hibernate Validator from Red Hat
CVE-2020-10693
5.3MEDIUM
What is CVE-2020-10693?
A vulnerability in Hibernate Validator (version 6.1.2.Final) allows attackers to exploit flaws in the message interpolation processor. This issue results in the evaluation of invalid Expression Language (EL) expressions as valid, thereby enabling the bypass of crucial input sanitation mechanisms. Consequently, it can lead to security risks by allowing injected content in error messages that fail to properly handle user-controlled data.
Affected Version(s)
hibernate-validator 6.1.2.Final
