← volver
CVE-2020-10693

CVE-2020-10693

CVSS 5.3 MEDIUMEPSS 2.3%CWE-20
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 5.3EPSS 2.3%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
06 may 2020Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
A flaw was found in Hibernate Validator version 6.1.2.Final. A bug in the message interpolation processor enables invalid EL expressions to be evaluated as if they were valid. This flaw allows attackers to bypass input sanitation (escaping, stripping) controls that developers may have put in place when handling user-controlled data in error messages.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →