<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Generator-Jhipster (&lt; 9.4.0) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/generator-jhipster--9.4.0/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 08 Oct 2026 19:26:04 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/generator-jhipster--9.4.0/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>SQL Injection in JHipster-Generated Reactive Applications</title><link>https://feed.craftedsignal.io/briefs/2026-10-jhipster-sql-injection/</link><pubDate>Thu, 08 Oct 2026 19:26:04 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-jhipster-sql-injection/</guid><description>JHipster-generated reactive applications are vulnerable to SQL injection via the 'sort' parameter in paginated endpoints, allowing authenticated attackers to execute arbitrary SQL commands.</description><content:encoded><![CDATA[<p>Applications generated by <code>generator-jhipster</code> (versions 7.0.0 through 9.2.0) that utilize the reactive stack (Spring WebFlux and Spring Data R2DBC) contain a critical SQL injection vulnerability. The flaw exists in the <code>EntityManager_reactive.java.ejs</code> template, which improperly handles the <code>sort</code> request parameter provided to paginated entity endpoints. Specifically, the application concatenates user-supplied sort properties directly into the SQL <code>ORDER BY</code> clause without validation or parameter binding. Because the generated code relies on the R2DBC simple query protocol, an attacker can terminate the intended query and inject arbitrary SQL statements, such as <code>UPDATE</code> or <code>DROP TABLE</code>. Authenticated users with low privileges, including those created via self-registration, can successfully exploit this to exfiltrate sensitive data (including password hashes) or destroy database tables, resulting in total loss of confidentiality, integrity, and availability for the backend database.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker authenticates to a JHipster-generated reactive application using a low-privileged user account.</li>
<li>Attacker identifies a paginated endpoint (e.g., <code>GET /api/products</code>) that utilizes the vulnerable <code>sort</code> query parameter.</li>
<li>Attacker crafts a malicious HTTP GET request, injecting SQL metacharacters (e.g., <code>;</code>, <code>--</code>) into the <code>sort</code> parameter (e.g., <code>?sort=id;DROP TABLE product;--</code>).</li>
<li>The application receives the request and the <code>EntityManager</code> component processes the unsanitized string within <code>createOrderByFields</code>.</li>
<li>The backend generates an SQL statement concatenating the malicious string directly into the <code>ORDER BY</code> clause.</li>
<li>The R2DBC driver executes the concatenated string as part of a simple query protocol execution.</li>
<li>The database executes the injected command, leading to unauthorized data exfiltration, modification, or table deletion.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>The vulnerability allows for arbitrary SQL execution on the database connected to the JHipster-generated application. Observed impacts include the exfiltration of sensitive table data, such as <code>jhi_user</code> password hashes, and the destruction of application data through <code>DROP TABLE</code> commands. The vulnerability affects any reactive monolith or microservice generated by <code>generator-jhipster</code> v7.0.0 through v9.2.0 that uses SQL and pagination.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize the regeneration of all affected reactive applications using a patched version of <code>generator-jhipster</code>. If an immediate patch for the generator is unavailable, implement input validation logic for the <code>sort</code> parameter to ensure only permitted field names are passed to the <code>EntityManager</code>. Monitor web server logs for HTTP requests to <code>/api/*</code> endpoints containing URL-encoded SQL metacharacters like <code>%3B</code>, <code>%2D%2D</code>, or <code>DROP</code>. Ensure that database service accounts used by these applications follow the principle of least privilege to limit the scope of potential SQL injection impact.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>sql-injection</category><category>web-vulnerability</category><category>cwe-89</category></item></channel></rss>