Vulnerability Description
generator-jhipster-entity-audit is a JHipster module to enable entity audit and audit log page. Prior to 5.9.1, generator-jhipster-entity-audit allows unsafe reflection when having Javers selected as Entity Audit Framework. If an attacker manages to place some malicious classes into the classpath and also has access to these REST interface for calling the mentioned REST endpoints, using these lines of code can lead to unintended remote code execution. This vulnerability is fixed in 5.9.1.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/jhipster/generator-jhipster-entity-audit/blob/e21e83135d10c77
- https://github.com/jhipster/generator-jhipster-entity-audit/security/advisories/
FAQ
What is CVE-2025-31119?
CVE-2025-31119 is a vulnerability with a CVSS score of 7.6 (HIGH). generator-jhipster-entity-audit is a JHipster module to enable entity audit and audit log page. Prior to 5.9.1, generator-jhipster-entity-audit allows unsafe reflection when having Javers selected as ...
How severe is CVE-2025-31119?
CVE-2025-31119 has been rated HIGH with a CVSS base score of 7.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-31119?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.