Medium severity6.1NVD Advisory· Published Mar 14, 2018· Updated Jun 17, 2026
CVE-2018-1000129
CVE-2018-1000129
Description
An XSS vulnerability exists in the Jolokia agent version 1.3.7 in the HTTP servlet that allows an attacker to execute malicious javascript in the victim's browser.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.jolokia:jolokia-coreMaven | >= 1.3.7, < 1.5.0 | 1.5.0 |
Affected products
2Patches
Vulnerability mechanics
References
7- github.com/rhuss/jolokia/commit/5895d5c137c335e6b473e9dcb9baf748851bbc5fnvdPatchThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2018:2669nvdThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2018:3817nvdThird Party AdvisoryWEB
- github.com/advisories/GHSA-hfpg-gqjw-779mghsaADVISORY
- jolokia.orgnvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2018-1000129ghsaADVISORY
- github.com/rhuss/jolokia/releases/tag/v1.5.0ghsaWEB
News mentions
0No linked articles in our index yet.