Files
CVEs-PoC/2014/CVE-2014-3558.md
T
2024-06-18 02:51:15 +02:00

18 lines
764 B
Markdown

### [CVE-2014-3558](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3558)
![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=%3D%20n%2Fa%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen)
### Description
ReflectionHelper (org.hibernate.validator.util.ReflectionHelper) in Hibernate Validator 4.1.0 before 4.2.1, 4.3.x before 4.3.2, and 5.x before 5.1.2 allows attackers to bypass Java Security Manager (JSM) restrictions and execute restricted reflection calls via a crafted application.
### POC
#### Reference
- https://hibernate.atlassian.net/browse/HV-912
#### Github
No PoCs found on GitHub currently.