Skip to content

hibernate-validator-6.2.4.Final.jar: 1 vulnerabilities (highest severity is: 9.8) #13

@dev-mend-for-github-com

Description

@dev-mend-for-github-com
Vulnerable Library - hibernate-validator-6.2.4.Final.jar

Path to dependency file: /apps/showcase/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/fasterxml/classmate/1.5.1/classmate-1.5.1.jar

Found in HEAD commit: b2f62067f2a5bcb5368dd789ad5e9ac984d3df90

Vulnerabilities

CVE Severity CVSS Dependency Type Fixed in (hibernate-validator version) Remediation Possible** Reachability
CVE-50240-896950 Critical 9.8 classmate-1.5.1.jar Transitive N/A*

*For some transitive vulnerabilities, there is no version of direct dependency with a fix. Check the "Details" section below to see if there is a version of transitive dependency where vulnerability is fixed.

**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation

Details

CVE-50240-896950

Vulnerable Library - classmate-1.5.1.jar

Library for introspecting types with full generic information including resolving of field and method types.

Library home page: https://github.com/FasterXML/java-classmate

Path to dependency file: /apps/showcase/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/fasterxml/classmate/1.5.1/classmate-1.5.1.jar

Dependency Hierarchy:

  • hibernate-validator-6.2.4.Final.jar (Root Library)
    • classmate-1.5.1.jar (Vulnerable Library)

Found in HEAD commit: b2f62067f2a5bcb5368dd789ad5e9ac984d3df90

Found in base branch: master

Vulnerability Details

Created automatically by the test suite

Publish Date: 2010-06-07

URL: CVE-50240-896950

CVSS 3 Score Details (9.8)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions