Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWo4anctZzZmcS1tcDdo

SQL injection in hibernate-core

A flaw was found in hibernate-core in versions prior to 5.3.20.Final and in 5.4.0.Final up to and including 5.4.23.Final. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SQL comments of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks. The highest threat from this vulnerability is to data confidentiality and integrity.

Permalink: https://github.com/advisories/GHSA-j8jw-g6fq-mp7h
JSON: https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWo4anctZzZmcS1tcDdo
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: about 2 years ago
Updated: about 1 year ago


CVSS Score: 7.4
CVSS vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Identifiers: GHSA-j8jw-g6fq-mp7h, CVE-2020-25638
References: Blast Radius: 38.2

Affected Packages

maven:org.hibernate:hibernate-core
Dependent packages: 3,469
Dependent repositories: 145,451
Downloads:
Affected Version Ranges: < 5.3.20.Final, >= 5.4.0.Final, < 5.4.24.Final
Fixed in: 5.3.20.Final, 5.4.24.Final
All affected versions: 5.4.2-0.Final, 5.4.2-1.Final, 5.4.2-2.Final, 5.4.2-3.Final
All unaffected versions: 5.4.33, 5.5.6