Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWo4anctZzZmcS1tcDdo
SQL injection in hibernate-core
A flaw was found in hibernate-core in versions prior to 5.3.20.Final and in 5.4.0.Final up to and including 5.4.23.Final. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SQL comments of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks. The highest threat from this vulnerability is to data confidentiality and integrity.
Permalink: https://github.com/advisories/GHSA-j8jw-g6fq-mp7hJSON: https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWo4anctZzZmcS1tcDdo
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: about 2 years ago
Updated: about 1 year ago
CVSS Score: 7.4
CVSS vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Identifiers: GHSA-j8jw-g6fq-mp7h, CVE-2020-25638
References:
- https://nvd.nist.gov/vuln/detail/CVE-2020-25638
- https://bugzilla.redhat.com/show_bug.cgi?id=1881353
- https://lists.debian.org/debian-lts-announce/2021/01/msg00000.html
- https://www.debian.org/security/2021/dsa-4908
- https://lists.apache.org/thread.html/r833c1276e41334fa675848a08daf0c61f39009f9f9a400d9f7006d44@%3Cdev.turbine.apache.org%3E
- https://lists.apache.org/thread.html/rf2378209c676a28b71f9b604a3b3517c448540b85367160e558ef9df@%3Ccommits.turbine.apache.org%3E
- https://www.oracle.com//security-alerts/cpujul2021.html
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://www.oracle.com/security-alerts/cpujul2022.html
- https://github.com/advisories/GHSA-j8jw-g6fq-mp7h
Affected Packages
maven:org.hibernate:hibernate-core
Dependent packages: 3,469Dependent repositories: 145,451
Downloads:
Affected Version Ranges: < 5.3.20.Final, >= 5.4.0.Final, < 5.4.24.Final
Fixed in: 5.3.20.Final, 5.4.24.Final
All affected versions: 5.4.2-0.Final, 5.4.2-1.Final, 5.4.2-2.Final, 5.4.2-3.Final
All unaffected versions: 5.4.33, 5.5.6