CVE Published: 07/11/2024 |
CVE Updated: 07/11/2024 |
CVE Year: 2023 Source: redhat |
Vendor: Red Hat |
Product: A-MQ Clients 2 Status : PUBLISHED
CVE-2023-1932 Description
A flaw was found in hibernate-validator\'s \'isValid\' method in the org.hibernate.validator.internal.constraintvalidators.hv.SafeHtmlValidator class, which can be bypassed by omitting the tag ending in a less-than character. Browsers may render an invalid html, allowing HTML injection or Cross-Site-Scripting (XSS) attacks.