Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 1465573 - (CVE-2017-7536) CVE-2017-7536 hibernate-validator: Privilege escalation when running under the security manager
CVE-2017-7536 hibernate-validator: Privilege escalation when running under th...
Status: NEW
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
impact=moderate,public=20170926,repor...
: Security
Depends On: 1576142 1470920 1472059 1576141
Blocks: 1465576 1493931 1520314
  Show dependency treegraph
 
Reported: 2017-06-27 12:26 EDT by Andrej Nemec
Modified: 2018-10-19 17:42 EDT (History)
94 users (show)

See Also:
Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
It was found that when the security manager's reflective permissions, which allows it to access the private members of the class, are granted to Hibernate Validator, a potential privilege escalation can occur. By allowing the calling code to access those private members without the permission an attacker may be able to validate an invalid instance and access the private member value via ConstraintViolation#getInvalidValue().
Story Points: ---
Clone Of:
Environment:
Last Closed:
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2017:2808 normal SHIPPED_LIVE Important: Red Hat JBoss Enterprise Application Platform security update 2017-09-26 18:39:54 EDT
Red Hat Product Errata RHSA-2017:2809 normal SHIPPED_LIVE Important: Red Hat JBoss Enterprise Application Platform security update 2017-09-26 18:51:56 EDT
Red Hat Product Errata RHSA-2017:2810 normal SHIPPED_LIVE Important: Red Hat JBoss Enterprise Application Platform security update 2017-09-26 17:58:02 EDT
Red Hat Product Errata RHSA-2017:2811 normal SHIPPED_LIVE Important: eap7-jboss-ec2-eap security update 2017-09-26 19:14:16 EDT
Red Hat Product Errata RHSA-2017:3141 normal SHIPPED_LIVE Important: rhvm-appliance security, bug fix, and enhancement update 2017-11-07 17:23:02 EST
Red Hat Product Errata RHSA-2017:3454 normal SHIPPED_LIVE Important: Red Hat JBoss Enterprise Application Platform 7.1.0 security update 2017-12-13 17:48:09 EST
Red Hat Product Errata RHSA-2017:3455 normal SHIPPED_LIVE Important: Red Hat JBoss Enterprise Application Platform 7.1.0 security update 2017-12-13 17:57:25 EST
Red Hat Product Errata RHSA-2017:3456 normal SHIPPED_LIVE Important: Red Hat JBoss Enterprise Application Platform 7.1.0 security update 2017-12-13 17:31:03 EST
Red Hat Product Errata RHSA-2017:3458 normal SHIPPED_LIVE Important: eap7-jboss-ec2-eap security update 2017-12-13 18:26:13 EST
Red Hat Product Errata RHSA-2018:2740 None None None 2018-09-24 17:46 EDT
Red Hat Product Errata RHSA-2018:2741 None None None 2018-09-24 18:04 EDT
Red Hat Product Errata RHSA-2018:2742 None None None 2018-09-24 18:08 EDT
Red Hat Product Errata RHSA-2018:2743 None None None 2018-09-24 18:10 EDT
Red Hat Product Errata RHSA-2018:2927 None None None 2018-10-16 11:20 EDT

  None (edit)
Description Andrej Nemec 2017-06-27 12:26:07 EDT
A vulnerability which allows for a potential privilege escalation was found in the Hibernate Validator. If a security manager is present and HV itself is allowed to access private members reflectively as per the SM's configuration, that'll allow calling code without that permission to get hold of private state. The attack vector is to declare a constraint on a private member using XML, validate an invalid instance of that type and access the private member value via ConstraintViolation#getInvalidValue().
Comment 1 Andrej Nemec 2017-06-27 12:26:41 EDT
Acknowledgments:

Name: Gunnar Morling (Red Hat)
Comment 2 Gunnar Morling 2017-07-06 09:10:27 EDT
Hi, we'd like to know how to proceed in this matter. Specifically we are about to release Hibernate Validator 6 (the reference implementation of Bean Validation 2.0) soon. Can we provide a fix for that issue in this new major version at this point in time? Our plan is to check for a specific permission which the caller must possess in order to validate constraints on private members when a security manager is enabled. We'd like to be sure though whether we can provide this solution while this bug record for Hibernate Validator 5.x still is open. Thanks!
Comment 11 Jason Shepherd 2017-09-06 23:30:33 EDT
Red Hat Mobile Platform Millicore component does run with a security manager enabled, marking it as not affected.
Comment 12 errata-xmlrpc 2017-09-26 13:59:53 EDT
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7.0.8

Via RHSA-2017:2810 https://access.redhat.com/errata/RHSA-2017:2810
Comment 13 errata-xmlrpc 2017-09-26 14:42:36 EDT
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7

Via RHSA-2017:2808 https://access.redhat.com/errata/RHSA-2017:2808
Comment 14 errata-xmlrpc 2017-09-26 14:54:53 EDT
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6

Via RHSA-2017:2809 https://access.redhat.com/errata/RHSA-2017:2809
Comment 15 errata-xmlrpc 2017-09-26 15:16:13 EDT
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7
  Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6

Via RHSA-2017:2811 https://access.redhat.com/errata/RHSA-2017:2811
Comment 16 errata-xmlrpc 2017-11-07 12:32:52 EST
This issue has been addressed in the following products:

  RHEV 4.X RHEV-H and Agents for RHEL-7

Via RHSA-2017:3141 https://access.redhat.com/errata/RHSA-2017:3141
Comment 17 errata-xmlrpc 2017-12-13 12:36:13 EST
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform

Via RHSA-2017:3456 https://access.redhat.com/errata/RHSA-2017:3456
Comment 18 errata-xmlrpc 2017-12-13 13:28:08 EST
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6

Via RHSA-2017:3454 https://access.redhat.com/errata/RHSA-2017:3454
Comment 19 errata-xmlrpc 2017-12-13 13:44:25 EST
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7

Via RHSA-2017:3455 https://access.redhat.com/errata/RHSA-2017:3455
Comment 20 errata-xmlrpc 2017-12-13 13:54:51 EST
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7
  Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6

Via RHSA-2017:3458 https://access.redhat.com/errata/RHSA-2017:3458
Comment 21 Salvatore Bonaccorso 2017-12-28 03:57:57 EST
Hi

Would it be possible to indicate where the issue was fixed? In Debian we ship libhibernate-validator-java and we would like to clarify if/how we are affected by the issue. Is there any furher reference?

Thank you already!

Regards,
Salvatore
Comment 23 Fabio Olive Leite 2017-12-28 12:19:16 EST
Setting needinfo to Bharti Kundal so that she sees it.
Comment 24 Bharti Kundal 2018-01-02 02:57:01 EST
(In reply to Salvatore Bonaccorso from comment #21)
> Hi
> 
> Would it be possible to indicate where the issue was fixed? In Debian we
> ship libhibernate-validator-java and we would like to clarify if/how we are
> affected by the issue. Is there any furher reference?
> 
> Thank you already!
> 
> Regards,
> Salvatore

Hi Salvatore,

The issue affected all the HV 5.x branches (so 5.2, 5.3, 5.4 are all affected). 6 is not.

It's fixed in the upstream 5.2 branch .The branch is here: https://github.com/hibernate/hibernate-validator/tree/5.2

Does this help?

Thanks and Regards,
Bharti
Comment 25 Salvatore Bonaccorso 2018-01-02 03:18:17 EST
Hi Bharti!

(In reply to Bharti Kundal from comment #24)
> (In reply to Salvatore Bonaccorso from comment #21)
> > Hi
> > 
> > Would it be possible to indicate where the issue was fixed? In Debian we
> > ship libhibernate-validator-java and we would like to clarify if/how we are
> > affected by the issue. Is there any furher reference?
> > 
> > Thank you already!
> > 
> > Regards,
> > Salvatore
> 
> Hi Salvatore,
> 
> The issue affected all the HV 5.x branches (so 5.2, 5.3, 5.4 are all
> affected). 6 is not.
> 
> It's fixed in the upstream 5.2 branch .The branch is here:
> https://github.com/hibernate/hibernate-validator/tree/5.2
> 
> Does this help?

Yes, thanks, that helps!

Regards,
Salvatore
Comment 31 errata-xmlrpc 2018-09-24 17:46:28 EDT
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform

Via RHSA-2018:2740 https://access.redhat.com/errata/RHSA-2018:2740
Comment 32 errata-xmlrpc 2018-09-24 18:04:21 EDT
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7

Via RHSA-2018:2741 https://access.redhat.com/errata/RHSA-2018:2741
Comment 33 errata-xmlrpc 2018-09-24 18:08:15 EDT
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 5

Via RHSA-2018:2742 https://access.redhat.com/errata/RHSA-2018:2742
Comment 34 errata-xmlrpc 2018-09-24 18:09:32 EDT
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6

Via RHSA-2018:2743 https://access.redhat.com/errata/RHSA-2018:2743
Comment 35 errata-xmlrpc 2018-10-16 11:19:30 EDT
This issue has been addressed in the following products:

  Red Hat Satellite 6.4 for RHEL 7

Via RHSA-2018:2927 https://access.redhat.com/errata/RHSA-2018:2927

Note You need to log in before you can comment on or make changes to this bug.