Executive brief
JHipster is a development platform and code generator for building web applications. This vulnerability allowed attackers to intercept and modify authentication responses to change their user role from standard user to administrator, bypassing server-side authorization checks. However, this advisory has been withdrawn by the JHipster project as the original report was found to be invalid.
Technical details
The vulnerability was initially reported as an improper access control issue (CWE-284, CWE-451) where the authentication endpoint (/api/account) returned a user's role information (authorities parameter) in the response without proper server-side verification. An attacker could intercept the authentication response, modify the authorities array from ROLE_USER to ROLE_ADMIN, and forward the modified response to the application. The attack required client-side response manipulation (local attack vector), no authentication, and no user interaction. However, the JHipster development team determined through investigation that the original vulnerability report was invalid and withdrew the advisory on 2025-08-04.
Affected products
- JHipster generator-jhipster before 8.9.0
Timeline
- 2025-07-25: disclosed
- 2025-08-04: advisory: Advisory withdrawn as original report found to be invalid