CVE-2020-4072
Last modified
CVE-2020-4072 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. In generator-jhipster-kotlin version 1.6.0 log entries are created for invalid password reset attempts. As the email is provided by a user and the api is public this can be used by an attacker to forge log entries. EPSS estimates a 1.21% chance of exploitation in the next 30 days.
Description
In generator-jhipster-kotlin version 1.6.0 log entries are created for invalid password reset attempts. As the email is provided by a user and the api is public this can be used by an attacker to forge log entries. This is vulnerable to https://cwe.mitre.org/data/definitions/117.html This problem affects only application generated with jwt or session authentication. Applications using oauth are not vulnerable. This issue has been fixed in version 1.7.0.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Jhipster | Generator-Jhipster-Kotlin | < 1.7.0 |
References
- https://github.com/jhipster/jhipster-kotlin/commit/426ccab85e7e0da562643200637b99b6a2a99449Patch, Third Party Advisory
- https://owasp.org/www-community/attacks/Log_InjectionTechnical Description
- https://www.baeldung.com/jvm-log-forgingTechnical Description
- https://github.com/jhipster/jhipster-kotlin/commit/426ccab85e7e0da562643200637b99b6a2a99449Patch, Third Party Advisory
- https://owasp.org/www-community/attacks/Log_InjectionTechnical Description
- https://www.baeldung.com/jvm-log-forgingTechnical Description
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-4072?
How severe is CVE-2020-4072?
How do I fix CVE-2020-4072?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-4062In Conjur OSS Helm Chart before 2.0.0, a recently identified…9
- CVE-2020-4066In Limdu before 0.95, the trainBatch function has a command …7.2
- CVE-2020-4067In coturn before version 4.5.1.3, there is an issue whereby …7.5
- CVE-2020-4068In APNSwift 1.0.0, calling APNSwiftSigner.sign(digest:) is l…9.8
- CVE-2020-4070In CSS Validator less than or equal to commit 54d68a1, there…5.4
- CVE-2020-4071In django-basic-auth-ip-whitelist before 0.3.4, a potential …2.4
- CVE-2020-4074In PrestaShop from version 1.5.0.0 and before version 1.7.6.…9.8
- CVE-2020-4075In Electron before versions 7.2.4, 8.2.4, and 9.0.0-beta21, …7.5
- CVE-2020-4076In Electron before versions 7.2.4, 8.2.4, and 9.0.0-beta21, …9
- CVE-2020-4077In Electron before versions 7.2.4, 8.2.4, and 9.0.0-beta21, …9.9
- CVE-2020-4079Combodo iTop is a web based IT Service Management tool. In i…7.7
- CVE-2020-4080HCL Verse v10 and v11 is susceptible to a Stored Cross-Site …6.1
Are you affected by CVE-2020-4072?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
