{"id":"GHSA-cmm8-gw4m-26cw","summary":"Withdrawn Advisory: JHipster allows privilege escalation via a modified authorities parameter","details":"## Withdrawn Advisory\nThis advisory has been withdrawn because the original report was found to be invalid. This link is maintained to preserve external references. For more information, see https://groups.google.com/g/jhipster-dev/c/ATSlWkEjw2w.\n\n## Original Description\n\nJHipster before v.8.9.0 allows privilege escalation via a modified authorities parameter. Upon registering in the JHipster portal and logging in as a standard user, the authorities parameter in the response from the api/account endpoint contains the value ROLE_USER. By manipulating the authorities parameter and changing its value to ROLE_ADMIN, the privilege is successfully escalated to an Admin level. This allowed the access to all admin-related functionalities in the application.","aliases":["CVE-2025-43712"],"modified":"2026-09-10T03:50:26.002836710Z","published":"2025-07-25T15:30:53Z","withdrawn":"2025-08-04T20:26:16Z","database_specific":{"github_reviewed_at":"2025-07-25T17:19:20Z","nvd_published_at":"2025-07-25T13:15:29Z","cwe_ids":["CWE-284","CWE-451"],"severity":"LOW","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-43712"},{"type":"WEB","url":"https://firecompass.com/cve-2025-43712-jhipster-platform-privilege-escalation-vulnerability-discovered-by-firecompass-research-added-to-nist"},{"type":"PACKAGE","url":"https://github.com/jhipster/generator-jhipster"},{"type":"WEB","url":"https://github.com/jhipster/generator-jhipster/releases"},{"type":"WEB","url":"https://groups.google.com/g/jhipster-dev/c/ATSlWkEjw2w"},{"type":"WEB","url":"https://medium.com/@hritikgodara/cve-2025-43712-privilege-escalation-via-response-manipulation-in-the-jhipster-platform-5e18c0434def"}],"affected":[{"package":{"name":"generator-jhipster","ecosystem":"npm","purl":"pkg:npm/generator-jhipster"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"8.9.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/07/GHSA-cmm8-gw4m-26cw/GHSA-cmm8-gw4m-26cw.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"}]}