Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-10899

Опубликовано: 11 июн. 2019
Источник: redhat
CVSS3: 8.1
EPSS Низкий

Описание

A flaw was found in Jolokia versions from 1.2 to before 1.6.1. Affected versions are vulnerable to a system-wide CSRF. This holds true for properly configured instances with strict checking for origin and referrer headers. This could result in a Remote Code Execution attack.

A flaw was found in Jolokia, versions 1.2 through 1.6.0, where Jolokia did not correctly handle checking for origin and referrer headers when strict checking was enabled. An attacker could use this vulnerability to conduct cross-site request forgery or further attacks.

Отчет

In Red Hat OpenStack Platform, jolokia is not enabled by default and, when enabled, the jolokia endpoints do not rely on CORS for security. Therefore, the impact has been reduced to Low and no updates will be provided at this time for the RHOSP jolokia package.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
JBoss Developer Studio 11jolokia-coreOut of support scope
Red Hat AMQ Broker 7jolokia-coreAffected
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo)opendaylightWill not fix
Red Hat JBoss Data Virtualization 6jolokia-coreNot affected
Red Hat OpenStack Platform 10 (Newton)opendaylightWill not fix
Red Hat OpenStack Platform 12 (Pike)opendaylightWill not fix
Red Hat OpenStack Platform 13 (Queens)opendaylightFix deferred
Red Hat OpenStack Platform 8 (Liberty)opendaylightWill not fix
Red Hat OpenStack Platform 9 (Mitaka)opendaylightWill not fix
Red Hat Fuse 6.3jolokia-coreFixedRHSA-2019:280417.09.2019

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1601037jolokia: system-wide CSRF that could lead to Remote Code Execution

EPSS

Процентиль: 84%
0.02129
Низкий

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
nvd
больше 6 лет назад

A flaw was found in Jolokia versions from 1.2 to before 1.6.1. Affected versions are vulnerable to a system-wide CSRF. This holds true for properly configured instances with strict checking for origin and referrer headers. This could result in a Remote Code Execution attack.

CVSS3: 8.1
github
больше 3 лет назад

Cross-Site Request Forgery in Jolokia

EPSS

Процентиль: 84%
0.02129
Низкий

8.1 High

CVSS3