Jhipster

    Dashboard / Vendors

    Products: 4
    Vulnerabilities: 5
    Known Exploited: 0
    1
    Critical Level Threats
    2
    High Level Threats
    1
    Medium Level Threats
    1
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2025-43712

    JHipster before v.8.9.0 allows privilege escalation via a modified authorities parameter. Upon registering in the JHipster portal and logging in as a standard user, the authorities parameter in the response from the api/account endpoint contains the value ROLE_USER. By manipulating the authorities parameter and changing its value to ROLE_ADMIN, the privilege is successfully escalated to an Admin level. This allowed the access to all admin-related functionalities in the application. NOTE: this is disputed by the Supplier because there is no privilege escalation in the context of the JHipster backend (the report only demonstrates that, after using JHipster to generate an application, one can make a non-functional admin screen visible in the front end of that application).

    Last Modified: Apr 15, 2026
    Published: Jul 25, 2025

    CVE-2015-20110

    JHipster generator-jhipster before 2.23.0 allows a timing attack against validateToken due to a string comparison that stops at the first character that is different. Attackers can guess tokens by brute forcing one character at a time and observing the timing. This of course drastically reduces the search space to a linear amount of guesses based on the token length times the possible characters.

    Last Modified: Nov 21, 2024
    Published: Oct 31, 2023

    CVE-2022-24815

    SQL Injection when creating an application with Reactive SQL backend

    Last Modified: Apr 22, 2025
    Published: Apr 11, 2022

    CVE-2020-4072

    Log Forging in generator-jhipster-kotlin

    Last Modified: Nov 21, 2024
    Published: Jun 25, 2020

    CVE-2019-16303

    A class generated by the Generator in JHipster before 6.3.0 and JHipster Kotlin through 1.1.0 produces code that uses an insecure source of randomness (apache.commons.lang3 RandomStringUtils). This allows an attacker (if able to obtain their own password reset URL) to compute the value for all other password resets for other accounts, thus allowing privilege escalation or account takeover.

    Last Modified: Nov 21, 2024
    Published: Sep 13, 2019
    Items Per Page
    Jhipster Vulnerabilities & Security CVEs | CVE-DB