SCA: security update for generator-jhipster (GHSA-qjmq-8hjr-qcv6)

high Tenable Self-Hosted Container Security Plugin ID 418178

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- JHipster is a development platform to quickly generate, develop, & deploy modern web applications &
microservice architectures. SQL Injection vulnerability in entities for applications generated with the
option "reactive with Spring WebFlux" enabled and an SQL database using r2dbc. Applications created
without "reactive with Spring WebFlux" and applications with NoSQL databases are not affected. Users who
have generated a microservice Gateway using the affected version may be impacted as Gateways are reactive
by default. Currently, SQL injection is possible in the findAllBy(Pageable pageable, Criteria criteria)
method of an entity repository class generated in these applications as the where clause using Criteria
for queries are not sanitized and user input is passed on as it is by the criteria. This issue has been
patched in v7.8.1. Users unable to upgrade should be careful when combining criterias and conditions as
the root of the issue lies in the `EntityManager.java` class when creating the where clause via
`Conditions.just(criteria.toString())`. `just` accepts the literal string provided. Criteria's `toString`
method returns a plain string and this combination is vulnerable to sql injection as the string is not
sanitized and will contain whatever used passed as input using any plain SQL. (CVE-2022-24815)

See Also

https://github.com/advisories/GHSA-qjmq-8hjr-qcv6

Plugin Details

Severity: High

ID: 418178

Version: Revision 1.7

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.12

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2022-24815

CVSS v3

Risk Factor: High

Base Score: 8.1

Temporal Score: 7.3

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 4/7/2022

Vulnerability Publication Date: 4/7/2022

Reference Information

CVE: CVE-2022-24815

cwe: CWE-89