CVE-2018-10899

HIGH

Jolokia 1.2-1.6.0 - Cross-Site Request Forgery

Title source: llm
STIX 2.1

Description

A flaw was found in Jolokia versions from 1.2 to before 1.6.1. Affected versions are vulnerable to a system-wide CSRF. This holds true for properly configured instances with strict checking for origin and referrer headers. This could result in a Remote Code Execution attack.

References (11)

Core 11
Core References
Issue Tracking, Third Party Advisory x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10899
Release Notes, Vendor Advisory x_refsource_confirm
https://jolokia.org/changes-report.html#a1.6.1
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2019:2413
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2019:2804

Scores

CVSS v3 8.1
EPSS 0.0209
EPSS Percentile 84.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-352 CWE-20
Status published
Products (3)
jolokia/jolokia 1.2.0 - 1.6.1
org.jolokia/jolokia-core 1.2 - 1.6.1Maven
redhat/openstack 13
Published Aug 01, 2019
Tracked Since Feb 18, 2026