CVE-2018-10899: Input Validation
A flaw was found in Jolokia versions from 1.2 to before 1.6.1. Affected versions are vulnerable to a system-wide CSRF. This holds true for properly configured instances with strict checking for origin and referrer headers. This could result in a Remote Code Execution attack.
Other sources
A flaw was found in Jolokia versions from 1.2. up to and including 1.6.0. Affected versions are vulnerable to a system-wide CSRF. This holds true for properly configured instances with strict checking for origin and referrer headers. This could result in a Remote Code Execution attack.
— Red Hat
A flaw was found in Jolokia, versions 1.2 through 1.6.0, where Jolokia did not correctly handle checking for origin and referrer headers when strict checking was enabled. An attacker could use this vulnerability to conduct cross-site request forgery or further attacks.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/jolokiato a version that resolves this vulnerability.Fixed in 1.6.1 - Upgrade
Upgrade
Jolokiato a version that resolves this vulnerability.Fixed in 1.6.1
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2018-10899?
The severity of CVE-2018-10899 is high with a CVSS score of 8.1.
Is my version of Jolokia affected by CVE-2018-10899?
If you are using Jolokia versions from 1.2 to before 1.6.1, your version is affected by CVE-2018-10899.
How can I fix CVE-2018-10899?
To fix CVE-2018-10899, update Jolokia to version 1.6.1 or later.
What is the Common Weakness Enumeration (CWE) ID for CVE-2018-10899?
The CWE ID for CVE-2018-10899 is CWE-352 and CWE-20.
Where can I find more information about CVE-2018-10899?
You can find more information about CVE-2018-10899 at the following references: [Reference 1](https://jolokia.org/#Minor_updates_coming_with_1.6.1), [Reference 2](https://access.redhat.com/errata/RHSA-2019:2413), [Reference 3](https://access.redhat.com/security/cve/cve-2018-10899).