Skip to main content

Vendor archive

jhipster CVEs

Beta · best-effort

4 CVEs tagged to vendor jhipster1 Critical, 2 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2015-20110

Published Oct 31, 2023

JHipster generator-jhipster before 2.23.0 allows a timing attack against validateToken due to a string comparison that stops at the first character that is different. Attackers ca…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-24815

Published Apr 11, 2022

JHipster is a development platform to quickly generate, develop, & deploy modern web applications & microservice architectures. SQL Injection vulnerability in entities for applica…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2020-4072

Published Jun 25, 2020

In generator-jhipster-kotlin version 1.6.0 log entries are created for invalid password reset attempts. As the email is provided by a user and the api is public this can be used b…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1