{"id":"CVE-2023-1932","summary":"Hibernate-validator: rendering of invalid html with safehtml leads to html injection and xss","details":"A flaw was found in hibernate-validator's 'isValid' method in the org.hibernate.validator.internal.constraintvalidators.hv.SafeHtmlValidator class, which can be bypassed by omitting the tag ending in a less-than character. Browsers may render an invalid html, allowing HTML injection or Cross-Site-Scripting (XSS) attacks.","aliases":["GHSA-x83m-pf6f-pf9g"],"modified":"2026-08-12T03:51:45.817381064Z","published":"2024-11-07T10:00:51.745Z","database_specific":{"cna_assigner":"redhat","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/1xxx/CVE-2023-1932.json"},"references":[{"type":"WEB","url":"https://access.redhat.com/downloads/content/package-browser/"},{"type":"WEB","url":"https://access.redhat.com/jbossnetwork/restricted/listSoftware.html"},{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/CVE-2023-1932"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/1xxx/CVE-2023-1932.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-1932"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1809444"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/hibernate/hibernate-validator","events":[{"introduced":"0"},{"fixed":"a883dcd11d7f9d8bdd8a2069a54cddd9213051c6"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"6.2"}],"source":"CPE_RANGE","cpe":"cpe:2.3:a:hibernate:hibernate-validator:*:*:*:*:*:*:*:*"}}],"versions":["6.2.0.CR1","6.1.6.Final","6.1.5.Final","6.1.4.Final","6.1.3.Final","6.1.2.Final","6.1.1.Final","6.1.0.Final","6.1.0.Alpha6","6.1.0.Alpha5","6.1.0.Alpha4","6.1.0.Alpha3","6.1.0.Alpha2","6.1.0.Alpha1","6.0.9.Final","6.0.8.Final","6.0.7.Final","6.0.6.Final","6.0.5.Final","6.0.4.Final","6.0.3.Final","6.0.2.Final","6.0.1.Final","6.0.0.CR3","6.0.0.CR2","6.0.0.CR1","6.0.0.Beta2","6.0.0.Beta1","6.0.0.Alpha2","6.0.0.Alpha1","5.2.2.Final","5.3.0.Alpha1","5.2.1.Final","5.2.0.Final","5.2.0.CR1","5.2.0.Beta1","5.2.0.Alpha1","4.2.0.Final","5.1.1.Final","5.1.0.Final","5.1.0.CR1","5.1.0.Beta1","5.0.1.Final","5.1.0.Alpha1","5.0.0.Final","5.0.0.CR5","5.0.0.CR4","5.0.0.CR3","5.0.0.CR2","5.0.0.CR1","5.0.0.Beta1","5.0.0.Alpha2","4.3.0.Final","5.0.0.Alpha1","4.3.0.CR1","4.3.0.Beta1","4.3.0.Alpha1","4.2.0.CR1","4.2.0.Beta2","pre-validator3-removal","4.2.0.Beta1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-1932.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}