CVE-2019-16303
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
A class generated by the Generator in JHipster before 6.3.0 and JHipster Kotlin through 1.1.0 produces code that uses an insecure source of randomness (apache.commons.lang3 RandomStringUtils). This allows an attacker (if able to obtain their own password reset URL) to compute the value for all other password resets for other accounts, thus allowing privilege escalation or account takeover.
Una clase generada mediante el Generator en JHipster versiones anteriores a 6.3.0 y JHipster Kotlin versiones hasta 1.1.0, produce código que utiliza una fuente no segura de aleatoriedad (apache.commons.lang3 RandomStringUtils). Esto permite a un atacante (si es capaz de obtener su propia URL de restablecimiento de contraseña) calcular el valor de todos los demás restablecimientos de contraseña para otras cuentas, permitiendo la escalada de privilegios o la toma de control de la cuenta.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-09-13 CVE Reserved
- 2019-09-13 CVE Published
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-338: Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
CAPEC
References (8)
URL | Date | SRC |
---|---|---|
https://github.com/jhipster/generator-jhipster/issues/10401 | 2024-08-05 | |
https://github.com/jhipster/jhipster-kotlin/issues/183 | 2024-08-05 |
URL | Date | SRC |
---|---|---|
https://github.com/jhipster/generator-jhipster/commit/88448b85fd3e8e49df103f0061359037c2c68ea7 | 2023-11-07 |
URL | Date | SRC |
---|---|---|
https://www.jhipster.tech/2019/09/13/jhipster-release-6.3.0.html | 2023-11-07 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Jhipster Search vendor "Jhipster" | Jhipster Search vendor "Jhipster" for product "Jhipster" | < 6.3.0 Search vendor "Jhipster" for product "Jhipster" and version " < 6.3.0" | - |
Affected
| ||||||
Jhipster Search vendor "Jhipster" | Jhipster Kotlin Search vendor "Jhipster" for product "Jhipster Kotlin" | <= 1.1.0 Search vendor "Jhipster" for product "Jhipster Kotlin" and version " <= 1.1.0" | - |
Affected
|