CVE-2025-31119

CVSS 3.1 Score 7.6 of 10 (high)

Details

Published Apr 3, 2025
Updated: Apr 7, 2025
CWE ID 470

Summary

CVE-2025-31119 is a vulnerability affecting the generator-jhipster-entity-audit module, version prior to 5.9.1. This JHipster module is used for enabling entity audit and audit log pages. The issue lies in the module's handling of Javers as the Entity Audit Framework, which allows for unsafe reflection. An attacker who can place malicious classes into the classpath and access certain REST interfaces can potentially execute remote code using specific lines of code. This risk is mitigated in version 5.9.1.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share