Lucene search

K
githubGitHub Advisory DatabaseGHSA-8GRG-Q944-CCH5
HistoryFeb 10, 2022 - 11:05 p.m.

SQL Injection in Hibernate ORM

2022-02-1023:05:04
CWE-89
GitHub Advisory Database
github.com
46
hibernate
sql injection
jpa criteria api
unauthorized access
security flaw

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

42.5%

A flaw was found in Hibernate ORM in versions before 5.3.18, 5.4.18 and 5.5.0.Beta1. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SELECT or GROUP BY parts of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks.

Affected configurations

Vulners
Node
org.hibernatehibernate-coreRange5.5.0.Alpha15.5.0.Beta1
OR
org.hibernatehibernate-coreRange5.4.05.4.18
OR
org.hibernatehibernate-coreRange<5.3.18
VendorProductVersionCPE
org.hibernatehibernate-core*cpe:2.3:a:org.hibernate:hibernate-core:*:*:*:*:*:*:*:*

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

42.5%