Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

Upgrade Hibernate Validator to 6.1.0.Final #4362

Closed
RyanJChamberlain opened this issue Jan 9, 2020 · 1 comment
Closed

Upgrade Hibernate Validator to 6.1.0.Final #4362

RyanJChamberlain opened this issue Jan 9, 2020 · 1 comment
Milestone

Comments

@RyanJChamberlain
Copy link

6.0.17.FINAL has a known XSS vulnerability, version 6.1.0.FINAL is available to upgrade too.

CVE finding: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-10219

@jansupol
Copy link
Contributor

jansupol commented Apr 3, 2020

Filed CQ 21876 for hibernate-validator 6.1.2.Final and CQ 21874 for hibernate-validator-cdi.

@jansupol jansupol added this to the 2.31 milestone Apr 3, 2020
# for free to join this conversation on GitHub. Already have an account? # to comment
Projects
None yet
Development

No branches or pull requests

2 participants