CVE-2018-10899

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
01/08/2019
Last modified:
17/06/2026

Description

A flaw was found in Jolokia versions from 1.2 to before 1.6.1. Affected versions are vulnerable to a system-wide CSRF. This holds true for properly configured instances with strict checking for origin and referrer headers. This could result in a Remote Code Execution attack.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:jolokia:jolokia:*:*:*:*:*:*:*:* 1.2.0 (including) 1.6.1 (excluding)
cpe:2.3:a:redhat:openstack:13:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools