PT-2025-14791 · Jhipster · Generator-Jhipster-Entity-Audit

CVE-2025-31119

·

Published

2025-04-03

·

Updated

2025-04-04

CVSS v3.1

7.6

High

VectorAV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions generator-jhipster-entity-audit versions prior to 5.9.1
Description The issue allows for unsafe reflection when Javers is selected as the Entity Audit Framework. If an attacker can place malicious classes into the classpath and access the REST interface, they can potentially achieve unintended remote code execution by calling specific REST endpoints.
Recommendations For versions prior to 5.9.1, update to version 5.9.1 to resolve the issue. As a temporary workaround, consider restricting access to the REST interface to minimize the risk of exploitation.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-31119
GHSA-7RMP-3G9F-CVQ8

Affected Products

Generator-Jhipster-Entity-Audit