Логотип exploitDog
bind:CVE-2020-4072
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-4072

Количество 2

Количество 2

nvd логотип

CVE-2020-4072

больше 5 лет назад

In generator-jhipster-kotlin version 1.6.0 log entries are created for invalid password reset attempts. As the email is provided by a user and the api is public this can be used by an attacker to forge log entries. This is vulnerable to https://cwe.mitre.org/data/definitions/117.html This problem affects only application generated with jwt or session authentication. Applications using oauth are not vulnerable. This issue has been fixed in version 1.7.0.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-pfxf-wh96-fvjc

больше 5 лет назад

Log Forging in generator-jhipster-kotlin

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-4072

In generator-jhipster-kotlin version 1.6.0 log entries are created for invalid password reset attempts. As the email is provided by a user and the api is public this can be used by an attacker to forge log entries. This is vulnerable to https://cwe.mitre.org/data/definitions/117.html This problem affects only application generated with jwt or session authentication. Applications using oauth are not vulnerable. This issue has been fixed in version 1.7.0.

CVSS3: 5.3
0%
Низкий
больше 5 лет назад
github логотип
GHSA-pfxf-wh96-fvjc

Log Forging in generator-jhipster-kotlin

CVSS3: 5.3
0%
Низкий
больше 5 лет назад

Уязвимостей на страницу