Junglewise Threat Intelligence

CVE-2025-31119: generator-jhipster-entity-audit unsafe reflection in Javers audit

CVE-2025-31119 · Severity: low · CVSS 3.1 · Published 2025-04-04

Vendors: npm.

Executive brief

generator-jhipster-entity-audit is a code generator used by JHipster applications to add entity audit logging capabilities. The vulnerability allows an authenticated administrator to trigger remote code execution by specifying malicious class names in audit query parameters, provided an attacker has previously injected malicious classes into the application's classpath. This could result in complete system compromise.

Technical details

The vulnerability is an unsafe reflection flaw (CWE-470) in the Javers entity audit REST endpoints. User-supplied input (entityType and qualifiedName parameters) is passed directly to Class.forName() without whitelist validation to load entity classes. An attacker with ADMIN role who can place malicious classes in the classpath can trigger arbitrary class loading, causing static initializers to execute and achieve remote code execution. The vulnerability affects versions up to 5.9.0 and is fixed in 5.9.1. Exploitation requires both prior classpath manipulation and ADMIN-level access.

Affected products

  • JHipster generator-jhipster-entity-audit <=5.9.0

Timeline

  • 2025-04-03: disclosed: CVE-2025-31119 published
  • 2025-04-03: patched: Fix available in version 5.9.1

References