CVE-2018-10899

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
01/08/2019
Last modified:
07/11/2023

Description

A flaw was found in Jolokia versions from 1.2 to before 1.6.1. Affected versions are vulnerable to a system-wide CSRF. This holds true for properly configured instances with strict checking for origin and referrer headers. This could result in a Remote Code Execution attack.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:jolokia:jolokia:*:*:*:*:*:*:*:* 1.2.0 (including) 1.6.1 (excluding)
cpe:2.3:a:redhat:openstack:13:*:*:*:*:*:*:*