HTML Injection Vulnerability in Hibernate Validator
CVE-2023-1932 
6.1MEDIUM
What is CVE-2023-1932?
A flaw exists in the 'isValid' method within the SafeHtmlValidator class of Hibernate Validator that allows for potential HTML injection and Cross-Site Scripting (XSS) attacks. This vulnerability occurs due to the improper handling of HTML tags, specifically when tag endings are omitted in a less-than character format. Consequently, browsers may render invalid HTML, which could be exploited by attackers to inject malicious scripts, compromising the security of affected applications.
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
 Low
Availability:
 Low
Attack Vector:
Network
Attack Complexity:
 Low
Privileges Required:
 None
User Interaction:
 Required
Scope:
 Changed
Timeline
- Vulnerability published 
- Vulnerability Reserved 
Credit
Red Hat would like to thank Christian Kistner (SySS GmbH) and Moritz Bechler (SySS GmbH) for reporting this issue.