VYPR

Jolokia

by Jolokia

Source repositories

CVEs (3)

  • CVE-2018-10899HigAug 1, 2019
    risk 0.53cvss 8.1epss 0.03

    A flaw was found in Jolokia versions from 1.2 to before 1.6.1. Affected versions are vulnerable to a system-wide CSRF. This holds true for properly configured instances with strict checking for origin and referrer headers. This could result in a Remote Code Execution attack.

  • CVE-2018-1000129MedMar 14, 2018
    risk 0.35cvss 6.1epss 0.25

    An XSS vulnerability exists in the Jolokia agent version 1.3.7 in the HTTP servlet that allows an attacker to execute malicious javascript in the victim's browser.

  • CVE-2014-0168Oct 6, 2014
    risk 0.00cvss epss 0.01

    Cross-site request forgery (CSRF) vulnerability in Jolokia before 1.2.1 allows remote attackers to hijack the authentication of users for requests that execute MBeans methods via a crafted web page.