Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-31119

Опубликовано: 03 апр. 2025
Источник: nvd
CVSS3: 7.6
EPSS Низкий

Описание

generator-jhipster-entity-audit is a JHipster module to enable entity audit and audit log page. Prior to 5.9.1, generator-jhipster-entity-audit allows unsafe reflection when having Javers selected as Entity Audit Framework. If an attacker manages to place some malicious classes into the classpath and also has access to these REST interface for calling the mentioned REST endpoints, using these lines of code can lead to unintended remote code execution. This vulnerability is fixed in 5.9.1.

EPSS

Процентиль: 83%
0.01974
Низкий

7.6 High

CVSS3

Дефекты

CWE-470

Связанные уязвимости

CVSS3: 7.6
github
10 месяцев назад

generator-jhipster-entity-audit vulnerable to Unsafe Reflection when having Javers selected as Entity Audit Framework

EPSS

Процентиль: 83%
0.01974
Низкий

7.6 High

CVSS3

Дефекты

CWE-470