Remote Code Execution Vulnerability in JHipster Entity Audit Module
CVE-2025-31119

7.7HIGH

Key Information:

Vendor

Jhipster

Vendor
CVE Published:
3 April 2025

What is CVE-2025-31119?

The generator-jhipster-entity-audit module, utilized for enabling entity audit and creating audit log pages in JHipster applications, contains a vulnerability prior to version 5.9.1. When Javers is selected as the Entity Audit Framework, this module allows for unsafe reflection. If an attacker can introduce malicious classes into the application's classpath and has access to the REST interface to call specific endpoints, they may exploit this flaw to execute arbitrary code remotely. The vulnerability has been remedied in version 5.9.1.

Affected Version(s)

generator-jhipster-entity-audit < 5.9.1

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.