CVE-2019-16303
Summary
| CVE | CVE-2019-16303 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-09-14 00:15:00 UTC |
| Updated | 2023-11-07 03:05:00 UTC |
| Description | A class generated by the Generator in JHipster before 6.3.0 and JHipster Kotlin through 1.1.0 produces code that uses an insecure source of randomness (apache.commons.lang3 RandomStringUtils). This allows an attacker (if able to obtain their own password reset URL) to compute the value for all other password resets for other accounts, thus allowing privilege escalation or account takeover. |
Risk And Classification
Problem Types: CWE-338
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Pony Mail! | lists.apache.org | ||
| Release 6.3.0 | MISC | www.jhipster.tech | Release Notes, Vendor Advisory |
| [SECURITY] CWE-338: Vulnerability in JHipster Kotlin · Issue #183 · jhipster/jhipster-kotlin · GitHub | MISC | github.com | Exploit, Third Party Advisory |
| Pony Mail! | lists.apache.org | ||
| Pony Mail! | MLIST | lists.apache.org | |
| Account takeover and privilege escalation is possible in applications generated by generator-jhipster before 6.3.0. · Advisory · jhipster/generator-jhipster · GitHub | MISC | github.com | Third Party Advisory |
| Pony Mail! | MLIST | lists.apache.org | |
| Bug bounty for security advisory - thank you @JLLeitschuh · Issue #10401 · jhipster/generator-jhipster · GitHub | MISC | github.com | Exploit, Third Party Advisory |
| use new SecureRandom which uses non blocking /dev/urandom · jhipster/generator-jhipster@88448b8 · GitHub | MISC | github.com | Patch |
| Pony Mail! | lists.apache.org | ||
| Pony Mail! | MLIST | lists.apache.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 980765 Nodejs (npm) Security Update for generator-jhipster-kotlin (GHSA-j3rh-8vwq-wh84)