VDB
Sign up
MEDIUM5.3

GHSA-pfxf-wh96-fvjc

Log Forging in generator-jhipster-kotlin

Quick fix

GHSA-pfxf-wh96-fvjc — generator-jhipster-kotlin: upgrade to the fixed version with the command below.

npm install generator-jhipster-kotlin@1.7.0

Details

### Impact

We log the mail for invalid password reset attempts. As the email is provided by a user and the api is public this can be used by an attacker to forge log entries. This is vulnerable to https://cwe.mitre.org/data/definitions/117.html

This problem affects only application generated with jwt or session authentication. Applications using oauth are not vulnerable.

### Patches

version 1.7.0.

### Workarounds

In `AccountResource.kt` you should change the line

```kotlin log.warn("Password reset requested for non existing mail '$mail'"); ```

to

```kotlin log.warn("Password reset requested for non existing mail"); ```

### References

* https://cwe.mitre.org/data/definitions/117.html * https://owasp.org/www-community/attacks/Log_Injection * https://www.baeldung.com/jvm-log-forging

### For more information If you have any questions or comments about this advisory: * Open an issue in [jhipster kotlin](https://github.com/jhipster/jhipster-kotlin)

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/generator-jhipster-kotlin
Introduced in: 1.6.0Fixed in: 1.7.0
Fixnpm install generator-jhipster-kotlin@1.7.0

References