Loading
A flaw was found in hibernate-validator's 'isValid' method in the org.hibernate.validator.internal.constraintvalidators.hv.SafeHtmlValidator class, which can be bypassed by omitting the tag ending in a less-than character. Browsers may render an invalid html, allowing HTML injection or Cross-Site-Scripting (XSS) attacks.
Use CWE-79, Redhat vendor hub and Codeready Studio product page to widen CVE-2023-1932 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2021-4104, CVE-2020-10714 and CVE-2021-20218 for nearby disclosures in the same product family.