Skip to content

Account takeover and privilege escalation is possible in applications generated by generator-jhipster before 6.3.0.

Critical
jdubois published GHSA-mwp6-j9wf-968c Sep 13, 2019 · 1 comment

Package

npm jhipster-generator (NPM)

Affected versions

<= 6.2.0

Patched versions

6.3.0

Description

Account takeover and privilege escalation is possible in applications generated by generator-jhipster before 6.3.0. This is due to a vulnerability in the generated java classes: CWE-338: Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)

Generated applications must be manually patched, following instructions in the release notes: https://www.jhipster.tech/2019/09/13/jhipster-release-6.3.0.html

Severity

Critical

CVE ID

CVE-2019-16303

Weaknesses

No CWEs

Credits