JHipster is a code-generation framework for building full-stack Java applications, with vulnerabilities primarily affecting its generator tooling and the generated application artifacts it produces. The recurring exposure centers on application-layer defects including SQL injection, improper logging neutralization, weak authentication rate-limiting, and cryptographically weak random-number generation that can propagate from the generator into downstream applications. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Jhipster over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-16303CRITICAL A class generated by the Generator in JHipster before 6.3.0 and JHipster Kotlin through 1.1.0 produces code that uses an insecure source of randomness (apache.commons.lang3 RandomS | Sep 14, 2019 | 9.8 | 31 | NO | NO |
CVE-2022-24815HIGH JHipster is a development platform to quickly generate, develop, & deploy modern web applications & microservice architectures. SQL Injection vulnerability in entities for applicat | Apr 11, 2022 | 8.1 | 25 | NO | NO |
CVE-2015-20110HIGH JHipster generator-jhipster before 2.23.0 allows a timing attack against validateToken due to a string comparison that stops at the first character that is different. Attackers can | Oct 31, 2023 | 7.5 | 21 | NO | NO |
CVE-2020-4072MEDIUM In generator-jhipster-kotlin version 1.6.0 log entries are created for invalid password reset attempts. As the email is provided by a user and the api is public this can be used by | Jun 25, 2020 | 5.3 | 19 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Jhipster.
Media articles that mention a CVE ID that affects a product developed by Jhipster — matched by CVE ID, not by vendor name.