« Volver al listado

CVE-2025-32950

Estado: AnalizadaMedia (6.5)—

Jmix is a set of libraries and tools to speed up Spring Boot data-centric application development. In versions 1.0.0 to 1.6.1 and 2.0.0 to 2.3.4, attackers could manipulate the FileRef parameter to access files on the system where the Jmix application is deployed, provided the application server has the necessary permissions. This can be accomplished either by modifying the FileRef directly in the database or by supplying a harmful value in the fileRef parameter of the `/files` endpoint of the generic REST API. This issue has been patched in versions 1.6.2 and 2.4.0. A workaround is provided on the Jmix documentation website.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-32950",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-32950",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-04-24T19:56:35.680766Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "jmix-framework",
          "product": "jmix",
          "versions": [
            {
              "status": "affected",
              "version": ">= 1.0.0, < 1.6.2"
            },
            {
              "status": "affected",
              "version": ">= 2.0.0, < 2.4.0"
            }
          ]
        }
      ]
    }
  ],
  "published": "2025-04-22T18:15:59.793",
  "references": [
    {
      "url": "https://docs.jmix.io/jmix/files-vulnerabilities.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://docs.jmix.io/jmix/files-vulnerabilities.html#fix-path-traversal-in-jmix-application",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/jmix-framework/jmix/commit/6a66aa3adb967159a30d703e80403406f4c8f7a2",
      "tags": [
        "Patch"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/jmix-framework/jmix/commit/c589ef4e2b25620770b8036f4ad05f1a6250cb6a",
      "tags": [
        "Patch"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/jmix-framework/jmix/commit/cc97e6ff974b9e7af8160fab39cc5866169daa37",
      "tags": [
        "Patch"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/jmix-framework/jmix/commit/f4e6fb05bd245cf36f3e9319aaa0fcd540d024aa",
      "tags": [
        "Patch"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/jmix-framework/jmix/issues/3804",
      "tags": [
        "Issue Tracking"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/jmix-framework/jmix/issues/3836",
      "tags": [
        "Issue Tracking"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/jmix-framework/jmix/security/advisories/GHSA-jx4g-3xqm-62vh",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security-advisories@github.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-22"
        },
        {
          "lang": "en",
          "value": "CWE-35"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Jmix is a set of libraries and tools to speed up Spring Boot data-centric application development. In versions 1.0.0 to 1.6.1 and 2.0.0 to 2.3.4, attackers could manipulate the FileRef parameter to access files on the system where the Jmix application is deployed, provided the application server has the necessary permissions. This can be accomplished either by modifying the FileRef directly in the database or by supplying a harmful value in the fileRef parameter of the `/files` endpoint of the generic REST API. This issue has been patched in versions 1.6.2 and 2.4.0. A workaround is provided on the Jmix documentation website."
    },
    {
      "lang": "es",
      "value": "Jmix es un conjunto de librerías y herramientas para acelerar el desarrollo de aplicaciones centradas en datos en Spring Boot. En las versiones 1.0.0 a 1.6.1 y 2.0.0 a 2.3.4, los atacantes podían manipular el parámetro FileRef para acceder a los archivos del sistema donde se implementa la aplicación Jmix, siempre que el servidor de aplicaciones cuente con los permisos necesarios. Esto se puede lograr modificando FileRef directamente en la base de datos o proporcionando un valor dañino en el parámetro fileRef del endpoint `/files` de la API REST genérica. Este problema se ha corregido en las versiones 1.6.2 y 2.4.0. Se ofrece un workaround en el sitio web de documentación de Jmix."
    }
  ],
  "lastModified": "2026-06-17T09:12:51.120",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:haulmont:jmix_framework:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A877F67E-4952-4984-8F29-A5DFD0E3090A",
              "versionEndExcluding": "1.6.2",
              "versionStartIncluding": "1.0.0"
            },
            {
              "criteria": "cpe:2.3:a:haulmont:jmix_framework:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "266AE114-6141-48C3-BCBC-33C47FBE0B89",
              "versionEndExcluding": "2.4.0",
              "versionStartIncluding": "2.0.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security-advisories@github.com"
}