generator-jhipster-entity-audit@5.9.0 vulnerabilities

JHipster module to enable entity audit and audit log page

  • latest version

    5.10.0

  • latest non vulnerable version

  • first published

    9 years ago

  • latest version published

    16 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the generator-jhipster-entity-audit package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')

    generator-jhipster-entity-audit is a JHipster module to enable entity audit and audit log page

    Affected versions of this package are vulnerable to Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') via the entityType and qualifiedName parameters in REST endpoints. An attacker can execute arbitrary code by passing malicious class names that lead to unintended class loading.

    Note:

    This is only exploitable if the attacker manages to place some malicious classes into the classpath and also has access to these REST interface for calling the mentioned REST endpoints.

    How to fix Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')?

    Upgrade generator-jhipster-entity-audit to version 5.9.1 or higher.

    <5.9.1