Bug 1738673 (CVE-2019-10219)

Summary: CVE-2019-10219 hibernate-validator: safeHTML validator allows XSS
Product: [Other] Security Response Reporter: Laura Pardo <lpardo>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: aileenc, akoufoud, alazarot, almorale, anstephe, apo, asoldano, avibelli, bbaranow, bbuckingham, bcourt, bgeorges, bkearney, bmaxwell, brian.stansberry, btotty, cbyrne, cdewolf, chazlett, cmacedo, cmoulliard, darran.lofthouse, dbecker, dffrench, dkreling, dosoudil, drieden, drusso, etirelli, extras-orphan, ggaughan, gsmet, gvarsami, hhudgeon, ibek, ikanello, iweiss, janstey, java-sig-commits, jawilson, jbalunas, jcoleman, jjoyce, jmadigan, jochrist, jolee, jpallich, jperkins, jschatte, jschluet, jshepherd, jstastny, jwon, kbasil, kconner, krathod, kverlaen, kwills, ldimaggi, lef, lgao, lhh, loleary, lpeer, lthon, lzap, mburns, mhulan, mkolesni, mmccune, mnovotny, msochure, msvehla, mszynkie, ngough, nwallace, paradhya, pdrozd, pgallagh, pjindal, pmackay, psotirop, puntogil, pwright, rchan, rfreire, rguimara, rjerrido, rrajasek, rruss, rsvoboda, rsynek, rwagner, sclewis, scohen, sdaley, security-response-team, slinaber, smaestri, spinder, sthorger, tcunning, theute, tkirby, tom.jenkinson, trepel, twalsh, vhalbert
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: hibernate-validator 6.0.18.Final, hibernate-validator 6.1.0.Final Doc Type: If docs needed, set a value
Doc Text:
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
Story Points: ---
Clone Of: Environment:
Last Closed: 2020-01-21 08:09:36 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1745487    
Bug Blocks: 1713386    

Description Laura Pardo 2019-08-07 20:04:39 UTC
A vulnerability was found in hibernate-validator. The SafeHtml validator fails to properly sanitize payloads. This could result in an XSS attack.

Comment 1 Laura Pardo 2019-08-07 20:04:49 UTC
Acknowledgments:

Name: Dominik Mizyn (Samsung R&D Institute Poland)

Comment 2 Summer Long 2019-08-08 03:27:47 UTC
Statement:

Red Hat OpenStack Platform's OpenDaylight will not be updated for this flaw because it is being deprecated and is only receiving security fixes for Important and Critical flaws.

Comment 3 Jason Shepherd 2019-08-08 05:58:13 UTC
This vulnerability is out of security support scope for the following product:

 * Red Hat Mobile Application Platform

 Please refer to https://access.redhat.com/support/policy/updates/rhmap for more details

Comment 4 Joshua Padman 2019-08-12 01:49:58 UTC
This vulnerability is out of security support scope for the following products:
 * Red Hat Enterprise Application Platform 5
 * Red Hat Enterprise Application Platform 6
 * Red Hat JBoss Operations Network 3
 * Red Hat JBoss BPM Suite 6
 * Red Hat JBoss BRMS 5
 * Red Hat JBoss BRMS 6
 * Red Hat JBoss Fuse 6
 * Red Hat JBoss Fuse Service Works 6
 * Red Hat JBoss SOA Platform 5
 * JBoss Developer Studio 11

Please refer to https://access.redhat.com/support/policy/updates/jboss_notes for more details.

Comment 5 Joshua Padman 2019-08-12 01:51:07 UTC
This vulnerability is out of security support scope for the following product:
* Red Hat JBoss Data Virtualization & Services 6

Please refer to https://access.redhat.com/support/policy/updates/jboss_notes for more details.

Comment 14 Markus Koschany 2019-09-10 17:25:35 UTC
Hello,

which versions of hibernate-validator are affected? What is the fixing commit? I cannot find any recent commits regarding SafeHTML in https://github.com/hibernate/hibernate-validator

Thanks

Comment 20 Marek Novotny 2019-12-13 07:11:56 UTC
I looked for an usage of SafeHtml and there is no occurrence in the source code so marking RHDM and RHPAM as affected just on existence of hibernate-validator jar or dependency is invalid.

Searched the annotation class in sources:
"org.hibernate.validator.constraints.SafeHtml"

Comment 21 Paramvir jindal 2019-12-13 14:38:57 UTC
@Marek, Thank you for looking into it. I am closing the trackers created for RHDM/PAM and marking them as not affected.

Comment 23 errata-xmlrpc 2020-01-21 02:23:42 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform

Via RHSA-2020:0164 https://access.redhat.com/errata/RHSA-2020:0164

Comment 24 errata-xmlrpc 2020-01-21 02:56:16 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6

Via RHSA-2020:0159 https://access.redhat.com/errata/RHSA-2020:0159

Comment 25 errata-xmlrpc 2020-01-21 03:21:37 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8

Via RHSA-2020:0161 https://access.redhat.com/errata/RHSA-2020:0161

Comment 26 errata-xmlrpc 2020-01-21 03:46:24 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7

Via RHSA-2020:0160 https://access.redhat.com/errata/RHSA-2020:0160

Comment 27 Product Security DevOps Team 2020-01-21 08:09:36 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2019-10219

Comment 32 errata-xmlrpc 2020-02-06 08:35:07 UTC
This issue has been addressed in the following products:

  Red Hat Single Sign-On

Via RHSA-2020:0445 https://access.redhat.com/errata/RHSA-2020:0445

Comment 38 errata-xmlrpc 2020-05-18 10:25:54 UTC
This issue has been addressed in the following products:

  Red Hat Openshift Application Runtimes

Via RHSA-2020:2067 https://access.redhat.com/errata/RHSA-2020:2067

Comment 39 errata-xmlrpc 2020-05-26 16:09:15 UTC
This issue has been addressed in the following products:

  Red Hat Data Grid 7.3.6

Via RHSA-2020:2321 https://access.redhat.com/errata/RHSA-2020:2321

Comment 40 errata-xmlrpc 2020-12-16 12:12:18 UTC
This issue has been addressed in the following products:

  Red Hat Fuse 7.8.0

Via RHSA-2020:5568 https://access.redhat.com/errata/RHSA-2020:5568

Comment 41 humburgerlive 2023-11-20 08:53:30 UTC Comment hidden (spam)
Comment 42 Olivia 2024-02-21 07:58:12 UTC Comment hidden (spam)
Comment 43 tefew32367 2024-04-08 11:27:35 UTC Comment hidden (spam)
Comment 44 Andyyyyyy 2024-04-09 03:26:43 UTC Comment hidden (spam)
Comment 45 Owen 2024-04-09 03:27:23 UTC Comment hidden (spam)
Comment 46 Owen 2024-04-09 03:54:59 UTC Comment hidden (spam)
Comment 47 Andyyyyyy 2024-04-09 03:55:24 UTC Comment hidden (spam)
Comment 48 Andyyyyyy 2024-04-09 03:57:34 UTC Comment hidden (spam)
Comment 49 Owen 2024-04-09 04:00:11 UTC Comment hidden (spam)
Comment 50 Andyyyyyy 2024-04-09 04:02:25 UTC Comment hidden (spam)
Comment 51 Owen 2024-04-09 04:08:44 UTC Comment hidden (spam)
Comment 52 Andyyyyyy 2024-04-09 04:17:24 UTC Comment hidden (spam)
Comment 53 Owen 2024-04-09 04:17:56 UTC Comment hidden (spam)
Comment 54 Andyyyyyy 2024-04-09 04:29:14 UTC Comment hidden (spam)
Comment 55 Owen 2024-04-09 04:32:46 UTC Comment hidden (spam)
Comment 56 Andyyyyyy 2024-04-09 04:34:12 UTC Comment hidden (spam)
Comment 57 Owen 2024-04-09 04:39:14 UTC Comment hidden (spam)
Comment 58 Andyyyyyy 2024-04-09 04:58:06 UTC Comment hidden (spam)
Comment 59 Andyyyyyy 2024-04-09 05:15:30 UTC Comment hidden (spam)
Comment 60 Andyyyyyy 2024-04-09 05:24:50 UTC Comment hidden (spam)
Comment 61 Owen 2024-04-09 05:25:43 UTC Comment hidden (spam)
Comment 62 Owen 2024-04-09 05:32:51 UTC Comment hidden (spam)
Comment 63 Andyyyyyy 2024-04-09 05:33:40 UTC Comment hidden (spam)
Comment 64 Owen 2024-04-09 05:45:02 UTC Comment hidden (spam)
Comment 65 Owen 2024-04-09 05:48:41 UTC Comment hidden (spam)
Comment 66 Andyyyyyy 2024-04-09 05:49:23 UTC Comment hidden (spam)
Comment 67 Andyyyyyy 2024-04-09 05:56:23 UTC Comment hidden (spam)
Comment 68 Owen 2024-04-09 05:56:54 UTC Comment hidden (spam)
Comment 69 Owen 2024-04-09 06:04:08 UTC Comment hidden (spam)
Comment 70 Owen 2024-04-09 06:07:54 UTC Comment hidden (spam)
Comment 71 Andyyyyyy 2024-04-09 06:09:28 UTC Comment hidden (spam)
Comment 72 Owen 2024-04-09 06:11:06 UTC Comment hidden (spam)