CVE-2020-25638
SQL injection in hibernate-core
7.4
HIGH
CVSS 3.1
EPSS 0.68%
Description
A flaw was found in hibernate-core in versions prior to and including 5.4.23.Final. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SQL comments of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks. The highest threat from this vulnerability is to data confidentiality and integrity.
How to fix CVE-2020-25638
To remediate CVE-2020-25638, upgrade the affected package to a fixed version below.
- —upgrade to 3.6.10.Final-11 or later
- —upgrade to 3.6.10.Final-6+deb9u1 or later
- —upgrade to 3.6.10.Final-9+deb10u1 or later
- —upgrade to 5.4.24.Final or later
Is CVE-2020-25638 being exploited?
Low — EPSS is 0.7%, meaning exploitation activity has not been observed at scale.
Affected packages (4)
- from 0, < 3.6.10.Final-11
- from 0, < 3.6.10.Final-6+deb9u1
- from 0, < 3.6.10.Final-9+deb10u1
- >= 5.4.0.Final, < 5.4.24.Final
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.4 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N |