{"id":"GHSA-845h-985r-jrqh","summary":"Improper Authentication in Hibernate Validator","details":"ReflectionHelper (org.hibernate.validator.util.ReflectionHelper) in Hibernate Validator 4.1.0 before 4.2.1, 4.3.x before 4.3.2, and 5.x before 5.1.2 allows attackers to bypass Java Security Manager (JSM) restrictions and execute restricted reflection calls via a crafted application.","aliases":["CVE-2014-3558"],"modified":"2024-12-08T05:25:23.348447Z","published":"2022-05-14T01:18:38Z","database_specific":{"nvd_published_at":"2014-09-30T14:55:00Z","cwe_ids":["CWE-287"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2022-07-07T22:41:16Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2014-3558"},{"type":"WEB","url":"https://github.com/hibernate/hibernate-validator/commit/2c95d4ea0ef20977be249e31a4a4f4f4f71c945d"},{"type":"WEB","url":"https://github.com/hibernate/hibernate-validator/commit/67fdff14831c035c25e098fe14bd86523d17f726"},{"type":"WEB","url":"https://github.com/hibernate/hibernate-validator/commit/7e7131939a4361a7cad3e77ab89a8462132c561c"},{"type":"WEB","url":"https://github.com/hibernate/hibernate-validator/commit/c489416f699a46859c134796b3ccfea41ef3ce52"},{"type":"WEB","url":"https://github.com/hibernate/hibernate-validator/commit/c9525ca544b1281e2b7c7347e86e87c86dc1dc6e"},{"type":"WEB","url":"https://github.com/hibernate/hibernate-validator/commit/e8c42b689df8c6752d635d02c6518da3fece3870"},{"type":"WEB","url":"https://github.com/hibernate/hibernate-validator/commit/f97c2021a03c825abdeca1692f5be51e77e76a8f"},{"type":"WEB","url":"https://github.com/hibernate/hibernate-validator/commit/fd4eaed7fb930db6a5e4c03742b4b3adcfecc90e"},{"type":"PACKAGE","url":"https://github.com/hibernate/hibernate-validator"},{"type":"WEB","url":"https://github.com/victims/victims-cve-db/blob/master/database/java/2014/3558.yaml"},{"type":"WEB","url":"https://hibernate.atlassian.net/browse/HV-912"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2014-1285.html"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2014-1286.html"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2014-1287.html"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2014-1288.html"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2015-0125.html"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2015-0720.html"}],"affected":[{"package":{"name":"org.hibernate:hibernate-validator","ecosystem":"Maven","purl":"pkg:maven/org.hibernate/hibernate-validator"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.1.0"},{"fixed":"4.2.1"}]}],"versions":["4.1.0.Final","4.2.0.Beta1","4.2.0.Beta2","4.2.0.CR1","4.2.0.Final"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-845h-985r-jrqh/GHSA-845h-985r-jrqh.json"}},{"package":{"name":"org.hibernate:hibernate-validator","ecosystem":"Maven","purl":"pkg:maven/org.hibernate/hibernate-validator"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.3.0"},{"fixed":"4.3.2"}]}],"versions":["4.3.0.Final","4.3.1.Final"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-845h-985r-jrqh/GHSA-845h-985r-jrqh.json"}},{"package":{"name":"org.hibernate:hibernate-validator","ecosystem":"Maven","purl":"pkg:maven/org.hibernate/hibernate-validator"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.0.0"},{"fixed":"5.1.2"}]}],"versions":["5.0.0.Final","5.0.1.Final","5.0.2.Final","5.0.3.Final","5.1.0.Alpha1","5.1.0.Beta1","5.1.0.CR1","5.1.0.Final","5.1.1.Final"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-845h-985r-jrqh/GHSA-845h-985r-jrqh.json"}}],"schema_version":"1.9.0"}