A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
References
Link Providers
https://access.redhat.com/errata/RHSA-2020:0159 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2020:0160 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2020:0161 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2020:0164 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2020:0445 cve-icon cve-icon
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10219 cve-icon cve-icon
https://github.com/hibernate/hibernate-validator/commit/124b7dd6d9a4ad24d4d49f74701f05a13e56cee cve-icon cve-icon cve-icon
https://github.com/hibernate/hibernate-validator/commit/124b7dd6d9a4ad24d4d49f74701f05a13e56ceee cve-icon
https://github.com/hibernate/hibernate-validator/commit/20d729548511ac5cff6fd459f93de137195420fe cve-icon cve-icon cve-icon
https://github.com/poc-effectiveness/PoCAdaptation/tree/main/Adapted/CVE-2019-10219 cve-icon cve-icon
https://github.com/poc-effectiveness/PoCAdaptation/tree/main/Origin/CVE-2019-10219/exploit cve-icon cve-icon
https://lists.apache.org/thread.html/r4f8b4e2541be4234946e40d55859273a7eec0f4901e8080ce2406fe6%40%3Cnotifications.accumulo.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/r4f92d7f7682dcff92722fa947f9e6f8ba2227c5dc3e11ba09114897d%40%3Cnotifications.accumulo.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/r87b7e2d22982b4ca9f88f5f4f22a19b394d2662415b233582ed22ebf%40%3Cnotifications.accumulo.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/rb8dca19a4e52b60dab0ab21e2ff9968d78f4b84e4033824db1dd24b4%40%3Cpluto-scm.portals.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/rd418deda6f0ebe658c2015f43a14d03acb8b8c2c093c5bf6b880cd7c%40%3Cpluto-dev.portals.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/rf9c17c3efc4a376a96e9e2777eee6acf0bec28e2200e4b35da62de4a%40%3Cpluto-dev.portals.apache.org%3E cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2019-10219 cve-icon
https://security.netapp.com/advisory/ntap-20220210-0024/ cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2019-10219 cve-icon
https://www.oracle.com/security-alerts/cpujan2022.html cve-icon cve-icon
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2019-11-08T14:46:03.000Z

Updated: 2025-07-07T13:55:51.360Z

Reserved: 2019-03-27T00:00:00.000Z

Link: CVE-2019-10219

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-11-08T15:15:11.157

Modified: 2025-07-07T14:15:21.437

Link: CVE-2019-10219

cve-icon Redhat

Severity : Moderate

Publid Date: 2019-08-28T00:00:00Z

Links: CVE-2019-10219 - Bugzilla