Skip to content

fix(deps): update dependency org.hibernate:hibernate-core to 4.3.+ [security] - autoclosed - #2998

Closed
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/maven-org.hibernate-hibernate-core-vulnerability
Closed

fix(deps): update dependency org.hibernate:hibernate-core to 4.3.+ [security] - autoclosed#2998
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/maven-org.hibernate-hibernate-core-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Jun 11, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
org.hibernate:hibernate-core (source) 4.2.+4.3.+ age confidence

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


SQL injection in hibernate-core

CVE-2020-25638 / GHSA-j8jw-g6fq-mp7h

More information

Details

A flaw was found in hibernate-core in versions prior to 5.3.20.Final and in 5.4.0.Final up to and including 5.4.23.Final. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SQL comments of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks. The highest threat from this vulnerability is to data confidentiality and integrity.

Severity

  • CVSS Score: 7.4 / 10 (High)
  • Vector String: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


SQL Injection in Hibernate ORM

CVE-2019-14900 / GHSA-8grg-q944-cch5

More information

Details

A flaw was found in Hibernate ORM in versions before 5.3.18, 5.4.18 and 5.5.0.Beta1. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SELECT or GROUP BY parts of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks.

Severity

  • CVSS Score: 6.5 / 10 (Medium)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

hibernate/hibernate-orm (org.hibernate:hibernate-core)

v4.3.11.Final

Compare Source

v4.3.10.Final

Compare Source

v4.3.9.Final

Compare Source

v4.3.8.Final

Compare Source

v4.3.7.Final

Compare Source

v4.3.6.Final

Compare Source

v4.3.5.Final

Compare Source

v4.3.4.Final

Compare Source

v4.3.3.Final

Compare Source

v4.3.2.Final

Compare Source

v4.3.1.Final: Release

Compare Source

See the details at http://in.relation.to/Bloggers/HibernateORM431FinalRelease. See http://hibernate.org/orm/downloads/ for information on getting the artifacts.

v4.3.0.Final

Compare Source


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot changed the title fix(deps): update dependency org.hibernate:hibernate-core to 4.3.+ [security] fix(deps): update dependency org.hibernate:hibernate-core to 4.3.+ [security] - autoclosed Jun 12, 2026
@renovate renovate Bot closed this Jun 12, 2026
@renovate
renovate Bot deleted the renovate/maven-org.hibernate-hibernate-core-vulnerability branch June 12, 2026 01:49
@renovate renovate Bot changed the title fix(deps): update dependency org.hibernate:hibernate-core to 4.3.+ [security] - autoclosed fix(deps): update dependency org.hibernate:hibernate-core to 4.3.+ [security] Jun 18, 2026
@renovate renovate Bot reopened this Jun 18, 2026
@renovate
renovate Bot force-pushed the renovate/maven-org.hibernate-hibernate-core-vulnerability branch 2 times, most recently from 3debbe6 to 1ce1a2d Compare June 18, 2026 18:43
@renovate renovate Bot changed the title fix(deps): update dependency org.hibernate:hibernate-core to 4.3.+ [security] fix(deps): update dependency org.hibernate:hibernate-core to 4.3.+ [security] - autoclosed Jun 19, 2026
@renovate renovate Bot closed this Jun 19, 2026
@renovate renovate Bot changed the title fix(deps): update dependency org.hibernate:hibernate-core to 4.3.+ [security] - autoclosed fix(deps): update dependency org.hibernate:hibernate-core to 4.3.+ [security] Jun 24, 2026
@renovate renovate Bot reopened this Jun 24, 2026
@renovate
renovate Bot force-pushed the renovate/maven-org.hibernate-hibernate-core-vulnerability branch 2 times, most recently from 1ce1a2d to 5765490 Compare June 24, 2026 05:28
@renovate renovate Bot changed the title fix(deps): update dependency org.hibernate:hibernate-core to 4.3.+ [security] fix(deps): update dependency org.hibernate:hibernate-core to 4.3.+ [security] - autoclosed Jun 24, 2026
@renovate renovate Bot closed this Jun 24, 2026
@renovate renovate Bot changed the title fix(deps): update dependency org.hibernate:hibernate-core to 4.3.+ [security] - autoclosed fix(deps): update dependency org.hibernate:hibernate-core to 4.3.+ [security] Jun 24, 2026
@renovate renovate Bot reopened this Jun 24, 2026
@renovate
renovate Bot force-pushed the renovate/maven-org.hibernate-hibernate-core-vulnerability branch 2 times, most recently from 5765490 to 2e64a93 Compare June 24, 2026 15:13
@renovate
renovate Bot restored the renovate/maven-org.hibernate-hibernate-core-vulnerability branch June 24, 2026 15:14
@renovate renovate Bot changed the title fix(deps): update dependency org.hibernate:hibernate-core to 4.3.+ [security] fix(deps): update dependency org.hibernate:hibernate-core to 4.3.+ [security] - autoclosed Jun 24, 2026
@renovate renovate Bot closed this Jun 24, 2026
@renovate
renovate Bot deleted the renovate/maven-org.hibernate-hibernate-core-vulnerability branch June 24, 2026 17:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants