{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/jhipster/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["JHipster"],"_cs_severities":["high"],"_cs_tags":["vulnerability","web-application","sql-injection","xss"],"_cs_type":"advisory","_cs_vendors":["JHipster"],"content_html":"\u003cp\u003eThe BSI has reported multiple vulnerabilities within the JHipster platform. These security flaws allow a remote, authenticated attacker to perform Cross-Site Scripting (XSS) or SQL Injection (SQLi) attacks. These vulnerabilities primarily affect the integrity of applications generated or managed by the JHipster framework. Because these flaws are exploitable by authenticated users, they represent a significant risk to internal security, as malicious actors with low-privileged account access could escalate their impact or perform unauthorized data manipulation. Defenders must audit applications generated with JHipster and ensure they are utilizing patched versions or applying necessary input sanitization and parameterization to mitigate these injection vectors.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of these vulnerabilities allows an attacker to inject arbitrary scripts into web pages viewed by other users (XSS) or manipulate backend database queries (SQLi). This can lead to session hijacking, unauthorized access to sensitive application data, and potential full application compromise, depending on the architecture and permissions of the generated application.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security and development teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eInventory all applications currently utilizing JHipster to identify versions exposed to these vulnerabilities.\u003c/li\u003e\n\u003cli\u003eReview and sanitize all application inputs to prevent SQL injection and ensure proper output encoding to block XSS attempts.\u003c/li\u003e\n\u003cli\u003eMonitor web server and application logs for suspicious characters in HTTP parameters, such as script tags or SQL syntax characters.\u003c/li\u003e\n\u003cli\u003eEnsure development teams apply security updates provided by the JHipster project as they become available.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-09T12:48:47Z","date_published":"2026-10-09T12:48:47Z","id":"https://feed.craftedsignal.io/briefs/2026-10-09-jhipster-vulnerabilities/","summary":"JHipster is affected by multiple vulnerabilities allowing a remote, authenticated attacker to execute Cross-Site Scripting (XSS) or SQL Injection attacks, compromising application integrity.","title":"Multiple Vulnerabilities in JHipster","url":"https://feed.craftedsignal.io/briefs/2026-10-09-jhipster-vulnerabilities/"},{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["generator-jhipster (v7.0.0-v9.2.0)","generator-jhipster (\u003c 9.4.0)","react-jhipster (\u003c= 1.0.3)"],"_cs_severities":["high"],"_cs_tags":["sql-injection","web-vulnerability","cwe-89"],"_cs_type":"advisory","_cs_vendors":["JHipster"],"content_html":"\u003cp\u003eApplications generated by \u003ccode\u003egenerator-jhipster\u003c/code\u003e (versions 7.0.0 through 9.2.0) that utilize the reactive stack (Spring WebFlux and Spring Data R2DBC) contain a critical SQL injection vulnerability. The flaw exists in the \u003ccode\u003eEntityManager_reactive.java.ejs\u003c/code\u003e template, which improperly handles the \u003ccode\u003esort\u003c/code\u003e request parameter provided to paginated entity endpoints. Specifically, the application concatenates user-supplied sort properties directly into the SQL \u003ccode\u003eORDER BY\u003c/code\u003e clause without validation or parameter binding. Because the generated code relies on the R2DBC simple query protocol, an attacker can terminate the intended query and inject arbitrary SQL statements, such as \u003ccode\u003eUPDATE\u003c/code\u003e or \u003ccode\u003eDROP TABLE\u003c/code\u003e. Authenticated users with low privileges, including those created via self-registration, can successfully exploit this to exfiltrate sensitive data (including password hashes) or destroy database tables, resulting in total loss of confidentiality, integrity, and availability for the backend database.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker authenticates to a JHipster-generated reactive application using a low-privileged user account.\u003c/li\u003e\n\u003cli\u003eAttacker identifies a paginated endpoint (e.g., \u003ccode\u003eGET /api/products\u003c/code\u003e) that utilizes the vulnerable \u003ccode\u003esort\u003c/code\u003e query parameter.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious HTTP GET request, injecting SQL metacharacters (e.g., \u003ccode\u003e;\u003c/code\u003e, \u003ccode\u003e--\u003c/code\u003e) into the \u003ccode\u003esort\u003c/code\u003e parameter (e.g., \u003ccode\u003e?sort=id;DROP TABLE product;--\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eThe application receives the request and the \u003ccode\u003eEntityManager\u003c/code\u003e component processes the unsanitized string within \u003ccode\u003ecreateOrderByFields\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe backend generates an SQL statement concatenating the malicious string directly into the \u003ccode\u003eORDER BY\u003c/code\u003e clause.\u003c/li\u003e\n\u003cli\u003eThe R2DBC driver executes the concatenated string as part of a simple query protocol execution.\u003c/li\u003e\n\u003cli\u003eThe database executes the injected command, leading to unauthorized data exfiltration, modification, or table deletion.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows for arbitrary SQL execution on the database connected to the JHipster-generated application. Observed impacts include the exfiltration of sensitive table data, such as \u003ccode\u003ejhi_user\u003c/code\u003e password hashes, and the destruction of application data through \u003ccode\u003eDROP TABLE\u003c/code\u003e commands. The vulnerability affects any reactive monolith or microservice generated by \u003ccode\u003egenerator-jhipster\u003c/code\u003e v7.0.0 through v9.2.0 that uses SQL and pagination.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the regeneration of all affected reactive applications using a patched version of \u003ccode\u003egenerator-jhipster\u003c/code\u003e. If an immediate patch for the generator is unavailable, implement input validation logic for the \u003ccode\u003esort\u003c/code\u003e parameter to ensure only permitted field names are passed to the \u003ccode\u003eEntityManager\u003c/code\u003e. Monitor web server logs for HTTP requests to \u003ccode\u003e/api/*\u003c/code\u003e endpoints containing URL-encoded SQL metacharacters like \u003ccode\u003e%3B\u003c/code\u003e, \u003ccode\u003e%2D%2D\u003c/code\u003e, or \u003ccode\u003eDROP\u003c/code\u003e. Ensure that database service accounts used by these applications follow the principle of least privilege to limit the scope of potential SQL injection impact.\u003c/p\u003e\n","date_modified":"2026-10-08T19:26:15Z","date_published":"2026-10-08T19:26:04Z","id":"https://feed.craftedsignal.io/briefs/2026-10-jhipster-sql-injection/","summary":"JHipster-generated reactive applications are vulnerable to SQL injection via the 'sort' parameter in paginated endpoints, allowing authenticated attackers to execute arbitrary SQL commands.","title":"SQL Injection in JHipster-Generated Reactive Applications","url":"https://feed.craftedsignal.io/briefs/2026-10-jhipster-sql-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - JHipster","version":"https://jsonfeed.org/version/1.1"}