Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xcxf-7q4p-cj26

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 8.1

Описание

Cross-Site Request Forgery in Jolokia

A flaw was found in Jolokia versions from 1.2 to before 1.6.1. Affected versions are vulnerable to a system-wide CSRF. This holds true for properly configured instances with strict checking for origin and referrer headers. This could result in a Remote Code Execution attack.

Пакеты

Наименование

org.jolokia:jolokia-core

maven
Затронутые версииВерсия исправления

>= 1.2, < 1.6.1

1.6.1

EPSS

Процентиль: 84%
0.02129
Низкий

8.1 High

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 8.1
redhat
больше 6 лет назад

A flaw was found in Jolokia versions from 1.2 to before 1.6.1. Affected versions are vulnerable to a system-wide CSRF. This holds true for properly configured instances with strict checking for origin and referrer headers. This could result in a Remote Code Execution attack.

CVSS3: 8.1
nvd
больше 6 лет назад

A flaw was found in Jolokia versions from 1.2 to before 1.6.1. Affected versions are vulnerable to a system-wide CSRF. This holds true for properly configured instances with strict checking for origin and referrer headers. This could result in a Remote Code Execution attack.

EPSS

Процентиль: 84%
0.02129
Низкий

8.1 High

CVSS3

Дефекты

CWE-352