Privilege Escalation in JHipster by Changing Authorities Parameter
CVE-2025-43712
2.9LOW
What is CVE-2025-43712?
A vulnerability in JHipster prior to version 8.9.0 permits unauthorized privilege escalation through manipulation of the authorities parameter returned by the api/account endpoint. When users register and log in, the standard response assigns them the ROLE_USER authority. However, by altering this parameter to ROLE_ADMIN, an attacker can gain administrative privileges, opening up access to sensitive functionalities within the application. This issue highlights the need for robust parameter validation and access control mechanisms.
Affected Version(s)
JHipster 0 < 8.9.0
