Unsafe Dependency Resolution Affecting generator-jhipster package, versions <6.3.1
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-JS-GENERATORJHIPSTER-536074
- published 28 Nov 2019
- disclosed 23 Sep 2019
- credit Unknown
Introduced: 23 Sep 2019
CVE NOT AVAILABLE CWE-494 Open this link in a new tabHow to fix?
Upgrade generator-jhipster
to version 6.3.1 or higher.
Overview
generator-jhipster is a development platform to generate, develop and deploy Spring Boot + Angular / React / Vue Web applications and Spring microservices.
Affected versions of this package are vulnerable to Unsafe Dependency Resolution. Generated code uses repository configuration that downloads over HTTP instead of HTTPS
References
CVSS Scores
version 3.1