FazBrowse GitHub Viewer | Trending |
URL:
| Home
Tools: [Download Repo ZIP]   [Original HTTPS Page]

[馃惛 Frogbot] Update version of org.hibernate:hibernate-core to 5.3.20.Final by gNurit 路 Pull Request #4 路 gNurit/BenchmarkJavaTestNurit 路 GitHub

[馃惛 Frogbot] Update version of org.hibernate:hibernate-core to 5.3.20.Final - #4

Open
gNurit wants to merge 1 commit into
masterfrom
frogbot-org.hibernate_hibernate-core-9b9500d36c9242a900e436b98d158eb2
Open

gNurit wants to merge 1 commit into
masterfrom
frogbot-org.hibernate_hibernate-core-9b9500d36c9242a900e436b98d158eb2

Conversation

gNurit commented May 4, 2025

Copy link
Copy Markdown
Owner

馃摝 Vulnerable Dependencies

Severity ID Contextual Analysis Direct Dependencies Impacted Dependency Fixed Versions

High
CVE-2020-25638 Missing Context org.hibernate:hibernate-core:3.6.10.Final org.hibernate:hibernate-core 3.6.10.Final [5.3.20.Final]
[5.4.24.Final]

馃敄 Details

Vulnerability Details

Policies: demo
Watch Name: github_wath
Contextual Analysis: Missing Context
Direct Dependencies: org.hibernate:hibernate-core:3.6.10.Final
Impacted Dependency: org.hibernate:hibernate-core:3.6.10.Final
Fixed Versions: [5.3.20.Final], [5.4.24.Final]
CVSS V3: 7.4

A flaw was found in hibernate-core in versions prior to and including 5.4.23.Final. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SQL comments of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks. The highest threat from this vulnerability is to data confidentiality and integrity.


gNurit commented May 4, 2025

Copy link
Copy Markdown
Owner Author


This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode characters
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants


Back | FazBrowse Home | New Git URL