High severity8.1NVD Advisory· Published Mar 14, 2018· Updated Jun 17, 2026
CVE-2018-1000130
CVE-2018-1000130
Description
A JNDI Injection vulnerability exists in Jolokia agent version 1.3.7 in the proxy mode that allows a remote attacker to run arbitrary Java code on the server.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.jolokia:jolokia-coreMaven | >= 1.3.7, < 1.5.0 | 1.5.0 |
Affected products
2- cpe:2.3:a:jolokia:webarchive_agent:1.3.7:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
7- access.redhat.com/errata/RHSA-2018:2669nvdThird Party AdvisoryWEB
- github.com/advisories/GHSA-rhqj-4pp8-vvgfghsaADVISORY
- jolokia.orgnvdRelease NotesVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2018-1000130ghsaADVISORY
- github.com/rhuss/jolokia/commit/1b360b8889f0ed51165a8d1ac55dd8e0aa2dfd4aghsaWEB
- github.com/rhuss/jolokia/commit/fd7b93da30c61a45bac10d8b311f1b79a74910f5ghsaWEB
- github.com/rhuss/jolokia/releases/tag/v1.5.0ghsaWEB
News mentions
0No linked articles in our index yet.