CVE-2025-32950

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Apr 22, 2025
Updated: Apr 23, 2025
CWE ID 22
CWE ID 35

Summary

CVE-2025-32950 is a vulnerability affecting versions 1.0.0 to 1.6.1 and 2.0.0 to 2.3.4 of Jmix, a library used for accelerating Spring Boot application development. The issue allows attackers to access system files on the server where the Jmix application is deployed through manipulation of the FileRef parameter. This can be done by either directly modifying the FileRef in the database or by providing a malicious value in the fileRef parameter of the `/files` endpoint of the generic REST API. The vulnerability has been addressed in versions 1.6.2 and 2.4.0. A workaround is available on the Jmix documentation website.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share