2017-10-16 12:31:07 -04:00
{
"CVE_data_meta" : {
2018-01-10 09:35:47 -05:00
"ASSIGNER" : "secalert@redhat.com" ,
"DATE_PUBLIC" : "2017-06-27T00:00:00" ,
2017-10-16 12:31:07 -04:00
"ID" : "CVE-2017-7536" ,
2018-01-10 09:35:47 -05:00
"STATE" : "PUBLIC"
} ,
"affects" : {
"vendor" : {
"vendor_data" : [
{
"product" : {
"product_data" : [
{
"product_name" : "hibernate-validator" ,
"version" : {
"version_data" : [
{
"version_value" : "5.2.x before 5.2.5 final"
} ,
{
"version_value" : "5.3.x"
} ,
{
"version_value" : "5.4.x"
}
]
}
}
]
} ,
"vendor_name" : "Red Hat, Inc."
}
]
}
2017-10-16 12:31:07 -04:00
} ,
"data_format" : "MITRE" ,
"data_type" : "CVE" ,
"data_version" : "4.0" ,
"description" : {
"description_data" : [
{
"lang" : "eng" ,
2018-01-10 10:05:57 -05:00
"value" : "In Hibernate Validator 5.2.x before 5.2.5 final, 5.3.x, and 5.4.x, it was found that when the security manager's reflective permissions, which allows it to access the private members of the class, are granted to Hibernate Validator, a potential privilege escalation can occur. By allowing the calling code to access those private members without the permission an attacker may be able to validate an invalid instance and access the private member value via ConstraintViolation#getInvalidValue()."
2018-01-10 09:35:47 -05:00
}
]
} ,
"problemtype" : {
"problemtype_data" : [
{
"description" : [
{
"lang" : "eng" ,
"value" : "CWE-592"
}
]
}
]
} ,
"references" : {
"reference_data" : [
{
2018-04-05 09:33:01 -04:00
"name" : "https://bugzilla.redhat.com/show_bug.cgi?id=1465573" ,
"refsource" : "CONFIRM" ,
2018-01-10 09:35:47 -05:00
"url" : "https://bugzilla.redhat.com/show_bug.cgi?id=1465573"
2018-01-11 06:04:34 -05:00
} ,
{
2018-04-05 09:33:01 -04:00
"name" : "RHSA-2017:2808" ,
"refsource" : "REDHAT" ,
2018-01-11 06:04:34 -05:00
"url" : "https://access.redhat.com/errata/RHSA-2017:2808"
} ,
{
2018-04-05 09:33:01 -04:00
"name" : "RHSA-2017:2809" ,
"refsource" : "REDHAT" ,
2018-01-11 06:04:34 -05:00
"url" : "https://access.redhat.com/errata/RHSA-2017:2809"
} ,
{
2018-04-05 09:33:01 -04:00
"name" : "RHSA-2017:2810" ,
"refsource" : "REDHAT" ,
2018-01-11 06:04:34 -05:00
"url" : "https://access.redhat.com/errata/RHSA-2017:2810"
} ,
{
2018-04-05 09:33:01 -04:00
"name" : "RHSA-2017:2811" ,
"refsource" : "REDHAT" ,
2018-01-11 06:04:34 -05:00
"url" : "https://access.redhat.com/errata/RHSA-2017:2811"
} ,
{
2018-04-05 09:33:01 -04:00
"name" : "RHSA-2017:3141" ,
"refsource" : "REDHAT" ,
2018-01-11 06:04:34 -05:00
"url" : "https://access.redhat.com/errata/RHSA-2017:3141"
} ,
{
2018-04-05 09:33:01 -04:00
"name" : "RHSA-2017:3454" ,
"refsource" : "REDHAT" ,
2018-01-11 06:04:34 -05:00
"url" : "https://access.redhat.com/errata/RHSA-2017:3454"
} ,
{
2018-04-05 09:33:01 -04:00
"name" : "RHSA-2017:3455" ,
"refsource" : "REDHAT" ,
2018-01-11 06:04:34 -05:00
"url" : "https://access.redhat.com/errata/RHSA-2017:3455"
} ,
{
2018-04-05 09:33:01 -04:00
"name" : "RHSA-2017:3456" ,
"refsource" : "REDHAT" ,
2018-01-11 06:04:34 -05:00
"url" : "https://access.redhat.com/errata/RHSA-2017:3456"
} ,
{
2018-04-05 09:33:01 -04:00
"name" : "RHSA-2017:3458" ,
"refsource" : "REDHAT" ,
2018-01-11 06:04:34 -05:00
"url" : "https://access.redhat.com/errata/RHSA-2017:3458"
} ,
2018-09-25 06:07:01 -04:00
{
"name" : "RHSA-2018:2740" ,
"refsource" : "REDHAT" ,
"url" : "https://access.redhat.com/errata/RHSA-2018:2740"
} ,
{
"name" : "RHSA-2018:2741" ,
"refsource" : "REDHAT" ,
"url" : "https://access.redhat.com/errata/RHSA-2018:2741"
} ,
{
"name" : "RHSA-2018:2742" ,
"refsource" : "REDHAT" ,
"url" : "https://access.redhat.com/errata/RHSA-2018:2742"
} ,
{
"name" : "RHSA-2018:2743" ,
"refsource" : "REDHAT" ,
"url" : "https://access.redhat.com/errata/RHSA-2018:2743"
} ,
2018-10-17 06:08:18 -04:00
{
"name" : "RHSA-2018:2927" ,
"refsource" : "REDHAT" ,
"url" : "https://access.redhat.com/errata/RHSA-2018:2927"
} ,
2018-12-12 06:07:39 -05:00
{
"name" : "RHSA-2018:3817" ,
"refsource" : "REDHAT" ,
"url" : "https://access.redhat.com/errata/RHSA-2018:3817"
} ,
2018-01-11 06:04:34 -05:00
{
2018-04-05 09:33:01 -04:00
"name" : "101048" ,
"refsource" : "BID" ,
2018-01-11 06:04:34 -05:00
"url" : "http://www.securityfocus.com/bid/101048"
} ,
{
2018-04-05 09:33:01 -04:00
"name" : "1039744" ,
"refsource" : "SECTRACK" ,
2018-01-11 06:04:34 -05:00
"url" : "http://www.securitytracker.com/id/1039744"
2017-10-16 12:31:07 -04:00
}
]
}
}