Jolokia 1.3.7

CPE Details

Jolokia 1.3.7
1.3.7
2019-07-29
11h42 +00:00
2019-07-29
11h42 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:jolokia:jolokia:1.3.7:*:*:*:*:*:*:*

Informations

Vendor

jolokia

Product

jolokia

Version

1.3.7

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2018-10899 2019-08-01
11h27 +00:00
A flaw was found in Jolokia versions from 1.2 to before 1.6.1. Affected versions are vulnerable to a system-wide CSRF. This holds true for properly configured instances with strict checking for origin and referrer headers. This could result in a Remote Code Execution attack.
8.8
High
CVE-2018-1000129 2018-03-14
12h00 +00:00
An XSS vulnerability exists in the Jolokia agent version 1.3.7 in the HTTP servlet that allows an attacker to execute malicious javascript in the victim's browser.
6.1
Medium