CVE-2025-32950
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Summary
CVE-2025-32950 is a vulnerability affecting versions 1.0.0 to 1.6.1 and 2.0.0 to 2.3.4 of Jmix, a library used for accelerating Spring Boot application development. The issue allows attackers to access system files on the server where the Jmix application is deployed through manipulation of the FileRef parameter. This can be done by either directly modifying the FileRef in the database or by providing a malicious value in the fileRef parameter of the `/files` endpoint of the generic REST API. The vulnerability has been addressed in versions 1.6.2 and 2.4.0. A workaround is available on the Jmix documentation website.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Jmix