CVEs (2)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
JHipster generator-jhipster before 2.23.0 allows a timing attack against validateToken due to a string comparison that stops at the first character that is different. Attackers can guess tokens by brute forcing one chara...Show more |
1Jhipster 2Jhipster Jhipster KotlinJun 17, 2026 Sep 14, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A class generated by the Generator in JHipster before 6.3.0 and JHipster Kotlin through 1.1.0 produces code that uses an insecure source of randomness (apache.commons.lang3 RandomStringUtils). This allows an attacker (if...Show more |