CVE-2019-10219

A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.

Published: 2019-11-08 Last update: 2025-07-07 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2019-10219 is rated Moderate Risk (53.3/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 1.67%). Mandatory action: Review affected assets and schedule remediation.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2019-10219

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2025-12-28 1.41% 1.67% +0.26%
2 2025-12-27 1.67% 1.41% -0.26%
3 2025-11-21 1.67%

Full EPSS history (26 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2019-10219

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
6.1 3.1 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Click to expand
Attack vector (AV:N)
Could be attacked over the internet or any normal routed network—not just someone sitting at the machine.
Attack complexity (AC:L)
Once they can reach the bug, pulling it off is straightforward—no weird race conditions or rare setup.
Privileges required (PR:N)
No account or special rights needed—anonymous or random user is enough.
User interaction (UI:R)
A real person has to do something—click, install, enable—otherwise it doesn’t land.
Scope (S:C)
Breaking this can reach past the original component and bite other resources—bigger blast radius.
Confidentiality (C:L)
Some sensitive info could get out, but not a total data dump.
Integrity (I:L)
Attackers could change some data, but it’s limited—not everything goes.
Availability (A:N)
Service keeps running; no real outage angle.
2.8 2.7 [email protected]
6.5 3.0 MEDIUM
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N Click to expand
Attack vector (AV:N)
Could be attacked over the internet or any normal routed network—not just someone sitting at the machine.
Attack complexity (AC:L)
Once they can reach the bug, pulling it off is straightforward—no weird race conditions or rare setup.
Privileges required (PR:N)
No account or special rights needed—anonymous or random user is enough.
User interaction (UI:N)
Nobody has to click “OK” or open a trap file; it can work without a victim helping.
Scope (S:U)
Damage stays in the same “trust bubble” as the broken component—no big spill into unrelated systems.
Confidentiality (C:L)
Some sensitive info could get out, but not a total data dump.
Integrity (I:L)
Attackers could change some data, but it’s limited—not everything goes.
Availability (A:N)
Service keeps running; no real outage angle.
3.9 2.5 [email protected]
4.3 2.0 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:M)
Exploitation needs some favorable conditions, but not exceptional ones.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:N)
No confidentiality impact.
Integrity impact (I:P)
Partial integrity impact.
Availability impact (A:N)
No availability impact.
8.6 2.9 [email protected]

Weakness enumeration for CVE-2019-10219

GitHub Security Advisory for CVE-2019-10219

GHSA-m8p2-495h-ccmh · Severity: medium · Ecosystem: maven — The SafeHtml annotation in Hibernate-Validator does not properly guard against XSS attacks

OS Trackers for CVE-2019-10219

vendor priority summary link
debian unimportant CVE-2019-10219 unimportant priority: Debian including 2 source packages (libhibernate-validator-java, libhibernate-validator4-java), 10 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): open 5, resolved 5. https://security-tracker.debian.org/tracker/CVE-2019-10219
redhat medium https://access.redhat.com/security/cve/CVE-2019-10219
ubuntu medium CVE-2019-10219 medium priority: Ubuntu including 1 source packages (libhibernate-validator-java), 18 status rows across 18 suites (bionic, disco, eoan, focal, groovy, hirsute, impish, jammy, kinetic, lunar, mantic, noble, oracular, plucky, questing, trusty, upstream, xenial): ignored 10, needs-triage 7, DNE 1. https://ubuntu.com/security/CVE-2019-10219

Affected software / configurations for CVE-2019-10219

Vendor Product Version Raw CPE
redhat hibernate_validator < 6.0.18 cpe:2.3:a:redhat:hibernate_validator:*:*:*:*:*:*:*:*
redhat hibernate_validator 6.1.0 cpe:2.3:a:redhat:hibernate_validator:6.1.0:alpha1:*:*:*:*:*:*
redhat hibernate_validator 6.1.0 cpe:2.3:a:redhat:hibernate_validator:6.1.0:alpha2:*:*:*:*:*:*
redhat hibernate_validator 6.1.0 cpe:2.3:a:redhat:hibernate_validator:6.1.0:alpha3:*:*:*:*:*:*
redhat hibernate_validator 6.1.0 cpe:2.3:a:redhat:hibernate_validator:6.1.0:alpha4:*:*:*:*:*:*
redhat hibernate_validator 6.1.0 cpe:2.3:a:redhat:hibernate_validator:6.1.0:alpha5:*:*:*:*:*:*
redhat hibernate_validator 6.1.0 cpe:2.3:a:redhat:hibernate_validator:6.1.0:alpha6:*:*:*:*:*:*
redhat fuse 1.0 cpe:2.3:a:redhat:fuse:1.0:*:*:*:*:*:*:*
redhat jboss_data_grid cpe:2.3:a:redhat:jboss_data_grid:-:*:*:*:text-only:*:*:*
redhat jboss_enterprise_application_platform cpe:2.3:a:redhat:jboss_enterprise_application_platform:-:*:*:*:text-only:*:*:*
redhat openshift_application_runtimes cpe:2.3:a:redhat:openshift_application_runtimes:-:*:*:*:text-only:*:*:*
redhat single_sign-on cpe:2.3:a:redhat:single_sign-on:-:*:*:*:text-only:*:*:*
redhat jboss_enterprise_application_platform 7.2 cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.2:*:*:*:*:*:*:*
redhat jboss_enterprise_application_platform 7.3 cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.3:*:*:*:*:*:*:*
netapp active_iq_unified_manager cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:linux:*:*
netapp active_iq_unified_manager cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*
netapp active_iq_unified_manager cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:windows:*:*
netapp management_services_for_element_software_and_netapp_hci cpe:2.3:a:netapp:management_services_for_element_software_and_netapp_hci:-:*:*:*:*:*:*:*
netapp snapcenter_plug-in cpe:2.3:a:netapp:snapcenter_plug-in:-:*:*:*:*:vmware_vsphere:*:*
netapp element cpe:2.3:o:netapp:element:-:*:*:*:*:vcenter_server:*:*
oracle access_manager 11.1.2.3.0 cpe:2.3:a:oracle:access_manager:11.1.2.3.0:*:*:*:*:*:*:*
oracle access_manager 12.2.1.3.0 cpe:2.3:a:oracle:access_manager:12.2.1.3.0:*:*:*:*:*:*:*
oracle access_manager 12.2.1.4.0 cpe:2.3:a:oracle:access_manager:12.2.1.4.0:*:*:*:*:*:*:*
oracle agile_engineering_data_management 6.2.1.0 cpe:2.3:a:oracle:agile_engineering_data_management:6.2.1.0:*:*:*:*:*:*:*
oracle agile_plm 9.3.3 cpe:2.3:a:oracle:agile_plm:9.3.3:*:*:*:*:*:*:*
oracle agile_plm 9.3.6 cpe:2.3:a:oracle:agile_plm:9.3.6:*:*:*:*:*:*:*
oracle agile_product_lifecycle_analytics 3.6.1 cpe:2.3:a:oracle:agile_product_lifecycle_analytics:3.6.1:*:*:*:*:*:*:*
oracle agile_product_lifecycle_management_integration_pack 3.6 cpe:2.3:a:oracle:agile_product_lifecycle_management_integration_pack:3.6:*:*:*:*:e-business_suite:*:*
oracle airlines_data_model 12.1.1.0.0 cpe:2.3:a:oracle:airlines_data_model:12.1.1.0.0:*:*:*:*:*:*:*
oracle airlines_data_model 12.2.0.1.0 cpe:2.3:a:oracle:airlines_data_model:12.2.0.1.0:*:*:*:*:*:*:*
oracle application_express 21.1.4 cpe:2.3:a:oracle:application_express:21.1.4:*:*:*:*:*:*:*
oracle application_performance_management 13.4.1.0 cpe:2.3:a:oracle:application_performance_management:13.4.1.0:*:*:*:*:*:*:*
oracle application_performance_management 13.5.1.0 cpe:2.3:a:oracle:application_performance_management:13.5.1.0:*:*:*:*:*:*:*
oracle application_testing_suite 13.3.0.1 cpe:2.3:a:oracle:application_testing_suite:13.3.0.1:*:*:*:*:*:*:*
oracle argus_analytics 8.2.1 cpe:2.3:a:oracle:argus_analytics:8.2.1:*:*:*:*:*:*:*
oracle argus_analytics 8.2.2 cpe:2.3:a:oracle:argus_analytics:8.2.2:*:*:*:*:*:*:*
oracle argus_analytics 8.2.3 cpe:2.3:a:oracle:argus_analytics:8.2.3:*:*:*:*:*:*:*
oracle argus_analytics 8.21 cpe:2.3:a:oracle:argus_analytics:8.21:*:*:*:*:*:*:*
oracle argus_insight 8.2.1 cpe:2.3:a:oracle:argus_insight:8.2.1:*:*:*:*:*:*:*
oracle argus_insight 8.2.2 cpe:2.3:a:oracle:argus_insight:8.2.2:*:*:*:*:*:*:*
oracle argus_insight 8.2.3 cpe:2.3:a:oracle:argus_insight:8.2.3:*:*:*:*:*:*:*
oracle argus_safety 8.2.1 cpe:2.3:a:oracle:argus_safety:8.2.1:*:*:*:*:*:*:*
oracle argus_safety 8.2.2 cpe:2.3:a:oracle:argus_safety:8.2.2:*:*:*:*:*:*:*
oracle argus_safety 8.2.3 cpe:2.3:a:oracle:argus_safety:8.2.3:*:*:*:*:*:*:*
oracle banking_apis 18.1 cpe:2.3:a:oracle:banking_apis:18.1:*:*:*:*:*:*:*
oracle banking_apis 18.2 cpe:2.3:a:oracle:banking_apis:18.2:*:*:*:*:*:*:*
oracle banking_apis 18.3 cpe:2.3:a:oracle:banking_apis:18.3:*:*:*:*:*:*:*
oracle banking_apis 19.1 cpe:2.3:a:oracle:banking_apis:19.1:*:*:*:*:*:*:*
oracle banking_apis 19.2 cpe:2.3:a:oracle:banking_apis:19.2:*:*:*:*:*:*:*
oracle banking_apis 20.1 cpe:2.3:a:oracle:banking_apis:20.1:*:*:*:*:*:*:*
oracle banking_apis 21.1 cpe:2.3:a:oracle:banking_apis:21.1:*:*:*:*:*:*:*
oracle banking_deposits_and_lines_of_credit_servicing 2.12.0 cpe:2.3:a:oracle:banking_deposits_and_lines_of_credit_servicing:2.12.0:*:*:*:*:*:*:*
oracle banking_digital_experience 17.2 cpe:2.3:a:oracle:banking_digital_experience:17.2:*:*:*:*:*:*:*
oracle banking_digital_experience 18.1 cpe:2.3:a:oracle:banking_digital_experience:18.1:*:*:*:*:*:*:*
oracle banking_digital_experience 18.3 cpe:2.3:a:oracle:banking_digital_experience:18.3:*:*:*:*:*:*:*
oracle banking_digital_experience 19.1 cpe:2.3:a:oracle:banking_digital_experience:19.1:*:*:*:*:*:*:*
oracle banking_digital_experience 19.2 cpe:2.3:a:oracle:banking_digital_experience:19.2:*:*:*:*:*:*:*
oracle banking_digital_experience 20.1 cpe:2.3:a:oracle:banking_digital_experience:20.1:*:*:*:*:*:*:*
oracle banking_digital_experience 21.1 cpe:2.3:a:oracle:banking_digital_experience:21.1:*:*:*:*:*:*:*
oracle banking_enterprise_default_management 2.6.2 cpe:2.3:a:oracle:banking_enterprise_default_management:2.6.2:*:*:*:*:*:*:*
oracle banking_enterprise_default_management 2.7.0 cpe:2.3:a:oracle:banking_enterprise_default_management:2.7.0:*:*:*:*:*:*:*
oracle banking_enterprise_default_management 2.7.1 cpe:2.3:a:oracle:banking_enterprise_default_management:2.7.1:*:*:*:*:*:*:*
oracle banking_enterprise_default_management 2.10.0 cpe:2.3:a:oracle:banking_enterprise_default_management:2.10.0:*:*:*:*:*:*:*
oracle banking_enterprise_default_management 2.12.0 cpe:2.3:a:oracle:banking_enterprise_default_management:2.12.0:*:*:*:*:*:*:*
oracle banking_enterprise_default_managment >= 2.3.0, <= 2.4.0 cpe:2.3:a:oracle:banking_enterprise_default_managment:*:*:*:*:*:*:*:*
oracle banking_loans_servicing 2.12.0 cpe:2.3:a:oracle:banking_loans_servicing:2.12.0:*:*:*:*:*:*:*
oracle banking_party_management 2.7.0 cpe:2.3:a:oracle:banking_party_management:2.7.0:*:*:*:*:*:*:*
oracle banking_platform >= 2.3.0, <= 2.4.1 cpe:2.3:a:oracle:banking_platform:*:*:*:*:*:*:*:*
oracle banking_platform 2.6.2 cpe:2.3:a:oracle:banking_platform:2.6.2:*:*:*:*:*:*:*
oracle banking_platform 2.7.0 cpe:2.3:a:oracle:banking_platform:2.7.0:*:*:*:*:*:*:*
oracle banking_platform 2.7.1 cpe:2.3:a:oracle:banking_platform:2.7.1:*:*:*:*:*:*:*
oracle bi_publisher 5.5.0.0.0 cpe:2.3:a:oracle:bi_publisher:5.5.0.0.0:*:*:*:*:*:*:*
oracle bi_publisher 11.1.1.9.0 cpe:2.3:a:oracle:bi_publisher:11.1.1.9.0:*:*:*:*:*:*:*
oracle bi_publisher 12.2.1.3.0 cpe:2.3:a:oracle:bi_publisher:12.2.1.3.0:*:*:*:*:*:*:*
oracle bi_publisher 12.2.1.4.0 cpe:2.3:a:oracle:bi_publisher:12.2.1.4.0:*:*:*:*:*:*:*
oracle big_data_spatial_and_graph 23.1 cpe:2.3:a:oracle:big_data_spatial_and_graph:23.1:*:*:*:*:*:*:*
oracle business_activity_monitoring 12.2.1.4.0 cpe:2.3:a:oracle:business_activity_monitoring:12.2.1.4.0:*:*:*:*:*:*:*
oracle business_intelligence 5.5.0.0.0 cpe:2.3:a:oracle:business_intelligence:5.5.0.0.0:*:*:*:enterprise:*:*:*
oracle business_intelligence 5.9.0.0.0 cpe:2.3:a:oracle:business_intelligence:5.9.0.0.0:*:*:*:enterprise:*:*:*
oracle business_intelligence 12.2.1.3.0 cpe:2.3:a:oracle:business_intelligence:12.2.1.3.0:*:*:*:enterprise:*:*:*

References for CVE-2019-10219

URL Tags
https://access.redhat.com/errata/RHSA-2020:0159 Third Party Advisory
https://access.redhat.com/errata/RHSA-2020:0160 Third Party Advisory
https://access.redhat.com/errata/RHSA-2020:0161 Third Party Advisory
https://access.redhat.com/errata/RHSA-2020:0164 Third Party Advisory
https://access.redhat.com/errata/RHSA-2020:0445 Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10219 Issue Tracking Third Party Advisory
https://github.com/hibernate/hibernate-validator/commit/124b7dd6d9a4ad24d4d49f74701f05a13e56cee
https://github.com/hibernate/hibernate-validator/commit/20d729548511ac5cff6fd459f93de137195420fe
https://github.com/poc-effectiveness/PoCAdaptation/tree/main/Adapted/CVE-2019-10219
https://github.com/poc-effectiveness/PoCAdaptation/tree/main/Origin/CVE-2019-10219/exploit
https://lists.apache.org/thread.html/r4f8b4e2541be4234946e40d55859273a7eec0f4901e8080ce2406fe6%40%3Cnotifications.accumulo.apache.org%3E
https://lists.apache.org/thread.html/r4f92d7f7682dcff92722fa947f9e6f8ba2227c5dc3e11ba09114897d%40%3Cnotifications.accumulo.apache.org%3E
https://lists.apache.org/thread.html/r87b7e2d22982b4ca9f88f5f4f22a19b394d2662415b233582ed22ebf%40%3Cnotifications.accumulo.apache.org%3E
https://lists.apache.org/thread.html/rb8dca19a4e52b60dab0ab21e2ff9968d78f4b84e4033824db1dd24b4%40%3Cpluto-scm.portals.apache.org%3E
https://lists.apache.org/thread.html/rd418deda6f0ebe658c2015f43a14d03acb8b8c2c093c5bf6b880cd7c%40%3Cpluto-dev.portals.apache.org%3E
https://lists.apache.org/thread.html/rf9c17c3efc4a376a96e9e2777eee6acf0bec28e2200e4b35da62de4a%40%3Cpluto-dev.portals.apache.org%3E
https://security.netapp.com/advisory/ntap-20220210-0024/ Third Party Advisory
https://www.oracle.com/security-alerts/cpujan2022.html Third Party Advisory
https://github.com/hibernate/hibernate-validator/commit/124b7dd6d9a4ad24d4d49f74701f05a13e56ceee
cvelogic Threat Intelligence