First published: Fri Jul 13 2018(Updated: )
A flaw was found in Jolokia versions from 1.2 to before 1.6.1. Affected versions are vulnerable to a system-wide CSRF. This holds true for properly configured instances with strict checking for origin and referrer headers. This could result in a Remote Code Execution attack.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jolokia Jolokia | >=1.2.0<1.6.1 | |
Redhat Openstack | =13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-10899 is high with a CVSS score of 8.1.
If you are using Jolokia versions from 1.2 to before 1.6.1, your version is affected by CVE-2018-10899.
To fix CVE-2018-10899, update Jolokia to version 1.6.1 or later.
The CWE ID for CVE-2018-10899 is CWE-352 and CWE-20.
You can find more information about CVE-2018-10899 at the following references: [Reference 1](https://jolokia.org/#Minor_updates_coming_with_1.6.1), [Reference 2](https://access.redhat.com/errata/RHSA-2019:2413), [Reference 3](https://access.redhat.com/security/cve/cve-2018-10899).