GHSA-pfxf-wh96-fvjc
Log Forging in generator-jhipster-kotlin
Quick fix
GHSA-pfxf-wh96-fvjc — generator-jhipster-kotlin: upgrade to the fixed version with the command below.
npm install generator-jhipster-kotlin@1.7.0Details
### Impact
We log the mail for invalid password reset attempts. As the email is provided by a user and the api is public this can be used by an attacker to forge log entries. This is vulnerable to https://cwe.mitre.org/data/definitions/117.html
This problem affects only application generated with jwt or session authentication. Applications using oauth are not vulnerable.
### Patches
version 1.7.0.
### Workarounds
In `AccountResource.kt` you should change the line
```kotlin log.warn("Password reset requested for non existing mail '$mail'"); ```
to
```kotlin log.warn("Password reset requested for non existing mail"); ```
### References
* https://cwe.mitre.org/data/definitions/117.html * https://owasp.org/www-community/attacks/Log_Injection * https://www.baeldung.com/jvm-log-forging
### For more information If you have any questions or comments about this advisory: * Open an issue in [jhipster kotlin](https://github.com/jhipster/jhipster-kotlin)
Are you affected?
Enter the version of the package you're using.
Affected packages
1.6.0Fixed in: 1.7.0npm install generator-jhipster-kotlin@1.7.0References
- https://github.com/jhipster/jhipster-kotlin/security/advisories/GHSA-pfxf-wh96-fvjc[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2020-4072[ADVISORY]
- https://github.com/jhipster/jhipster-kotlin/commit/426ccab85e7e0da562643200637b99b6a2a99449[WEB]
- https://owasp.org/www-community/attacks/Log_Injection[WEB]
- https://www.baeldung.com/jvm-log-forging[WEB]