Jhipster
jhipster
4 CVEs • 4 products
Products (4)
Click to collapseToggle
Products (4)
Click to collapse
CVEs (4)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
JHipster generator-jhipster before 2.23.0 allows a timing attack against validateToken due to a string comparison that stops at the first character that is different. Attackers can guess tokens by brute forcing one chara...Show more |
JHipster is a development platform to quickly generate, develop, & deploy modern web applications & microservice architectures. SQL Injection vulnerability in entities for applications generated with the option "reactive...Show more |
1Jhipster 1Generator Jhipster Kotlin Jun 17, 2026 Jun 25, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In generator-jhipster-kotlin version 1.6.0 log entries are created for invalid password reset attempts. As the email is provided by a user and the api is public this can be used by an attacker to forge log entries. This...Show more |
1Jhipster 2Jhipster Jhipster KotlinJun 17, 2026 Sep 14, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A class generated by the Generator in JHipster before 6.3.0 and JHipster Kotlin through 1.1.0 produces code that uses an insecure source of randomness (apache.commons.lang3 RandomStringUtils). This allows an attacker (if...Show more |