{"id":"GHSA-pfxf-wh96-fvjc","summary":"Log Forging in generator-jhipster-kotlin","details":"### Impact\n\nWe log the mail for invalid password reset attempts. \nAs the email is provided by a user and the api is public this can be used by an attacker to forge log entries.\nThis is vulnerable to https://cwe.mitre.org/data/definitions/117.html\n\nThis problem affects only application generated with jwt or session authentication. Applications using oauth are not vulnerable.\n\n### Patches\n\nversion 1.7.0.\n\n### Workarounds\n\nIn `AccountResource.kt` you should change the line\n\n```kotlin\n log.warn(\"Password reset requested for non existing mail '$mail'\");\n```\n\nto \n\n```kotlin\n log.warn(\"Password reset requested for non existing mail\");\n```\n\n### References\n\n* https://cwe.mitre.org/data/definitions/117.html\n* https://owasp.org/www-community/attacks/Log_Injection\n* https://www.baeldung.com/jvm-log-forging\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue in [jhipster kotlin](https://github.com/jhipster/jhipster-kotlin)","aliases":["CVE-2020-4072"],"modified":"2026-07-08T06:29:01.683446013Z","published":"2020-06-25T20:02:51Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-117"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2020-06-25T20:02:31Z"},"references":[{"type":"WEB","url":"https://github.com/jhipster/jhipster-kotlin/security/advisories/GHSA-pfxf-wh96-fvjc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-4072"},{"type":"WEB","url":"https://github.com/jhipster/jhipster-kotlin/commit/426ccab85e7e0da562643200637b99b6a2a99449"},{"type":"WEB","url":"https://owasp.org/www-community/attacks/Log_Injection"},{"type":"WEB","url":"https://www.baeldung.com/jvm-log-forging"}],"affected":[{"package":{"name":"generator-jhipster-kotlin","ecosystem":"npm","purl":"pkg:npm/generator-jhipster-kotlin"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.6.0"},{"fixed":"1.7.0"}]}],"versions":["1.6.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/06/GHSA-pfxf-wh96-fvjc/GHSA-pfxf-wh96-fvjc.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"}]}