APrieto034095 (Community Member) asked a question.

hibernate validator (CVE-2014-3558)

Hi,

Veracode SCA analysis detected a medium vulnerability on the hibernate-validator-4.3.2.Final.jar component. Looking at the CVE (CVE-2014-3558), the description says: "... hibernate Validator 4.1.0 before 4.2.1, 4.3.x before 4.3.2 ...". How does Veracode detect a vulnerability on that component if the CVE marked it as a safe one?


  • Thank you for your patience @APrieto034095 (Community Member)​ . This version of hibernate-validator has now been marked as not vulnerable and I have verified that your results reflect this.

     

    Please let me know if you have any remaining questions or concerns.

     

    Thank you,

    Boy Baukema

    Expand Post
    Selected as Best
  • Hi @APrieto034095 (Community Member)​ ,

     

    Veracode has dedicated Security Researchers that vet each vulnerability against the source code (if available) and against the released libraries. You can find more guidance, including upgrade advice, on the Veracode SCA Vulnerability Database: https://sca.veracode.com/vulnerability-database/security/remote-code-execution/os/sid-11419/summary (select hibernate4-validator from the Libraries section on the right hand side).

     

    Please let me know if you have any remaining questions or concerns.

     

    Thank you,

    Boy Baukema

    Expand Post
    • APrieto034095 (Community Member)

      Thanks for your quick response.

      But I’m still confused about that. Veracode says that hibernate-validator-4.3.2.Final.jar has a medium vulnerability, but the CVE related to that vulnerability says version 4.3.x before 4.3.2 are affected.
      • Hi @APrieto034095 (Community Member)​ ,

         

        Thank you for reporting this. I have looked into this and it does appear that we are incorrectly reporting hibernate-validator-4.3.2.Final as vulnerable. I have reported this to Veracode Engineering who will pick this up and make the necessary adjustments our database for future results, for now I would recommend that you mitigate this vulnerability as a Potential False Positive as documented here: https://help.veracode.com/reader/V_KSmNRUn6rtPwEJ1NXBmQ/OuRWNJs5rfWNzIQmMzK3Zg .

         

        Please let me know if you have any remaining questions or concerns.

         

        Thank you,

        Boy Baukema

        Expand Post
      • Thank you for your patience @APrieto034095 (Community Member)​ . This version of hibernate-validator has now been marked as not vulnerable and I have verified that your results reflect this.

         

        Please let me know if you have any remaining questions or concerns.

         

        Thank you,

        Boy Baukema

        Expand Post
        Selected as Best

Topics (4)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.