CVE-2025-32951

CVSS 3.1 Score 6.4 of 10 (medium)

Details

Published Apr 22, 2025
Updated: Apr 23, 2025
CWE ID 79

Summary

CVE-2025-32951 is a vulnerability affecting versions 1.0.0 to 1.6.1 and 2.0.0 to 2.3.4 of Jmix, a set of libraries and tools for Spring Boot development. Maliciously crafted file names ending in .html can manipulate the input parameter, leading to the Content-Type header being set to text/html. This potentially allows malicious JavaScript code to run in the user's browser. For an attack to be successful, a malicious file must first be uploaded. Versions 1.6.2 and 2.4.0 include the patch for this issue. A workaround is available on the Jmix documentation website.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share