CVE-2019-16303: Weak RNG
A class generated by the Generator in JHipster before 6.3.0 and JHipster Kotlin through 1.1.0 produces code that uses an insecure source of randomness (apache.commons.lang3 RandomStringUtils). This allows an attacker (if able to obtain their own password reset URL) to compute the value for all other password resets for other accounts, thus allowing privilege escalation or account takeover.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2019-16303.
What is the severity of CVE-2019-16303?
CVE-2019-16303 has a severity rating of 9.8 (critical).
Which software is affected by CVE-2019-16303?
JHipster versions before 6.3.0 and JHipster Kotlin versions up to and including 1.1.0 are affected by CVE-2019-16303.
How does CVE-2019-16303 impact security?
CVE-2019-16303 allows an attacker who can obtain their own password reset URL to compute the value for all other users' URLs.
How can CVE-2019-16303 be fixed?
To fix CVE-2019-16303, update JHipster and JHipster Kotlin to versions 6.3.0 and 1.1.0 respectively, or later.