CVE-2020-4072
Summary
| CVE | CVE-2020-4072 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-06-25 20:15:00 UTC |
| Updated | 2020-07-10 21:20:00 UTC |
| Description | In generator-jhipster-kotlin version 1.6.0 log entries are created for invalid password reset attempts. As the email is provided by a user and the api is public this can be used by an attacker to forge log entries. This is vulnerable to https://cwe.mitre.org/data/definitions/117.html This problem affects only application generated with jwt or session authentication. Applications using oauth are not vulnerable. This issue has been fixed in version 1.7.0. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| prevent log forging when doing password reset init request · jhipster/jhipster-kotlin@426ccab · GitHub |
MISC |
github.com |
Patch, Third Party Advisory |
| Log Injection Software Attack | OWASP Foundation |
MISC |
owasp.org |
Technical Description |
| Log Forging Vulnerability · Advisory · jhipster/jhipster-kotlin · GitHub |
CONFIRM |
github.com |
Third Party Advisory |
| JVM Log Forging | Baeldung |
MISC |
www.baeldung.com |
Technical Description |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 983181 Nodejs (npm) Security Update for generator-jhipster-kotlin (GHSA-pfxf-wh96-fvjc)