Description
A flaw was found in hibernate-core in versions prior to and including 5.4.23.Final. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SQL comments of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks. The highest threat from this vulnerability is to data confidentiality and integrity.
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=1881353
https://lists.apache.org/thread.html/r833c1276e41334fa675848a08daf0c61f39009f9f9a400d9f7006d44%40%3Cdev.turbine.apache.org%3E
https://lists.apache.org/thread.html/rf2378209c676a28b71f9b604a3b3517c448540b85367160e558ef9df%40%3Ccommits.turbine.apache.org%3E
https://lists.debian.org/debian-lts-announce/2021/01/msg00000.html
https://www.debian.org/security/2021/dsa-4908
https://www.oracle.com//security-alerts/cpujul2021.html
https://www.oracle.com/security-alerts/cpuapr2022.html
https://www.oracle.com/security-alerts/cpujul2022.html
Related Vulnerabilities
CVE-2022-27340 Vulnerability in maven package net.mingsoft:ms-mcms
CVE-2019-3868 Vulnerability in maven package org.keycloak:keycloak-core
CVE-2020-7672 Vulnerability in npm package mosc
CVE-2023-42276 Vulnerability in maven package cn.hutool:hutool-json
CVE-2023-39106 Vulnerability in maven package com.alibaba.nacos:nacos-spring-context