CVE-2018-10899
Description
Jolokia versions 1.2 through 1.6.0 are vulnerable to a system-wide CSRF that bypasses origin and referrer header checks, potentially leading to Remote Code Execution.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Jolokia versions 1.2 through 1.6.0 are vulnerable to a system-wide CSRF that bypasses origin and referrer header checks, potentially leading to Remote Code Execution.
Vulnerability
Details
A flaw was discovered in Jolokia, a Java-based JMX-HTTP bridge, affecting versions from 1.2 up to (but not including) 1.6.1. The software is vulnerable to a system-wide Cross-Site Request Forgery (CSRF) attack. Notably, this vulnerability exists even in instances that have been properly configured with strict checking of the HTTP Origin and Referer headers, as the CSRF protection mechanism can be bypassed [1][2].
Attack
Vector
An attacker can exploit this CSRF vulnerability by crafting a malicious web page or link that, when visited by an authenticated user with access to the Jolokia endpoint, triggers unauthorized requests. Since the origin and referrer checks can be circumvented, the attacker's requests appear legitimate to the Jolokia instance. This does not require network access beyond the ability to deliver the malicious payload to the target user, who must have a valid session with the Jolokia service [2][3].
Impact
Successful exploitation allows the attacker to perform arbitrary JMX operations on the target Java application server. Because JMX can be used to invoke methods and modify system properties, this can lead to a full Remote Code Execution (RCE) attack, giving the attacker complete control over the affected JVM and the underlying host system [2][3].
Mitigation
The vulnerability is fixed in Jolokia version 1.6.1, which was released on 2019-05-01 [1]. Red Hat also addressed this issue in security updates for Red Hat Fuse and A-MQ (RHSAs-2019:2413 and 2019:2804) in August and September 2019 [3][4]. Users should immediately upgrade to Jolokia 1.6.1 or later, or apply the relevant vendor patches to mitigate the risk of exploitation.
AI Insight generated on May 22, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.jolokia:jolokia-coreMaven | >= 1.2, < 1.6.1 | 1.6.1 |
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
20- access.redhat.com/errata/RHSA-2019:2413ghsavendor-advisoryx_refsource_REDHATWEB
- access.redhat.com/errata/RHSA-2019:2804ghsavendor-advisoryx_refsource_REDHATWEB
- github.com/advisories/GHSA-xcxf-7q4p-cj26ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2018-10899ghsaADVISORY
- bugzilla.redhat.com/show_bug.cgighsax_refsource_CONFIRMWEB
- jolokia.org/changes-report.htmlghsax_refsource_CONFIRMWEB
- lists.apache.org/thread.html/1392fbebb4fbbec379a40d16e1288fe1e4c0289d257e5206051a3793%40%3Cissues.activemq.apache.org%3Emitremailing-listx_refsource_MLIST
- lists.apache.org/thread.html/1392fbebb4fbbec379a40d16e1288fe1e4c0289d257e5206051a3793@%3Cissues.activemq.apache.org%3EghsaWEB
- lists.apache.org/thread.html/r46f6dbc029f49e1f638c6eb82accb94b7f990d818cb3b3bc0007dd0a%40%3Cissues.activemq.apache.org%3Emitremailing-listx_refsource_MLIST
- lists.apache.org/thread.html/r46f6dbc029f49e1f638c6eb82accb94b7f990d818cb3b3bc0007dd0a@%3Cissues.activemq.apache.org%3EghsaWEB
- lists.apache.org/thread.html/r64701caec91c43efd7416d6bddef88447371101e00e8562741ede262%40%3Cissues.activemq.apache.org%3Emitremailing-listx_refsource_MLIST
- lists.apache.org/thread.html/r64701caec91c43efd7416d6bddef88447371101e00e8562741ede262@%3Cissues.activemq.apache.org%3EghsaWEB
- lists.apache.org/thread.html/r67cdc50af9caf89c9ebe1bde08393a343dcd89edba1c63677f68f43b%40%3Cissues.activemq.apache.org%3Emitremailing-listx_refsource_MLIST
- lists.apache.org/thread.html/r67cdc50af9caf89c9ebe1bde08393a343dcd89edba1c63677f68f43b@%3Cissues.activemq.apache.org%3EghsaWEB
- lists.apache.org/thread.html/rc169dac018d07e8ddf2a3bb2fd1efc6cbda4f83f1bbf7a8c798e7f4f%40%3Cissues.activemq.apache.org%3Emitremailing-listx_refsource_MLIST
- lists.apache.org/thread.html/rc169dac018d07e8ddf2a3bb2fd1efc6cbda4f83f1bbf7a8c798e7f4f@%3Cissues.activemq.apache.org%3EghsaWEB
- lists.apache.org/thread.html/rdb0a59d7851e721b75beea13d6488e345a3e2735838e89d9269d7d32%40%3Cissues.activemq.apache.org%3Emitremailing-listx_refsource_MLIST
- lists.apache.org/thread.html/rdb0a59d7851e721b75beea13d6488e345a3e2735838e89d9269d7d32@%3Cissues.activemq.apache.org%3EghsaWEB
- lists.apache.org/thread.html/rf33ffbba619a4281ce592a6ed259c07a557aefb4975619d83c4122ea%40%3Cissues.activemq.apache.org%3Emitremailing-listx_refsource_MLIST
- lists.apache.org/thread.html/rf33ffbba619a4281ce592a6ed259c07a557aefb4975619d83c4122ea@%3Cissues.activemq.apache.org%3EghsaWEB
News mentions
0No linked articles in our index yet.