CVE ID | Published | Description | Score | Severity |
---|---|---|---|---|
11h27 +00:00 |
A flaw was found in Jolokia versions from 1.2 to before 1.6.1. Affected versions are vulnerable to a system-wide CSRF. This holds true for properly configured instances with strict checking for origin and referrer headers. This could result in a Remote Code Execution attack. | 8.8 |
High |
|
12h00 +00:00 |
An XSS vulnerability exists in the Jolokia agent version 1.3.7 in the HTTP servlet that allows an attacker to execute malicious javascript in the victim's browser. | 6.1 |
Medium |