{"id":"CVE-2020-4072","aliases":["GHSA-pfxf-wh96-fvjc"],"url":"https://o3.security/vulnerability/CVE-2020-4072","summary":"Log Forging in generator-jhipster-kotlin","details":"In generator-jhipster-kotlin version 1.6.0 log entries are created for invalid password reset attempts. As the email is provided by a user and the api is public this can be used by an attacker to forge log entries. This is vulnerable to https://cwe.mitre.org/data/definitions/117.html This problem affects only application generated with jwt or session authentication. Applications using oauth are not vulnerable. This issue has been fixed in version 1.7.0.","published":"2020-06-25T20:15:11.350Z","modified":"2026-07-09T11:24:27.600463Z","cvss":{"score":5.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"npm","name":"generator-jhipster-kotlin","fixedVersion":"1.7.0"}],"fix":{"url":"https://github.com/jhipster/jhipster-kotlin/commit/426ccab85e7e0da562643200637b99b6a2a99449","label":"jhipster/jhipster-kotlin@426ccab"},"references":[{"type":"ADVISORY","url":"https://github.com/jhipster/jhipster-kotlin/security/advisories/GHSA-pfxf-wh96-fvjc"},{"type":"FIX","url":"https://github.com/jhipster/jhipster-kotlin/commit/426ccab85e7e0da562643200637b99b6a2a99449"},{"type":"ARTICLE","url":"https://owasp.org/www-community/attacks/Log_Injection"},{"type":"ARTICLE","url":"https://www.baeldung.com/jvm-log-forging"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-09T11:24:27.600463Z"}}