VulnerabilityModified
CVE-2018-1000129
An XSS vulnerability exists in the Jolokia agent version 1.3.7 in the HTTP servlet that allows an attacker to execute malicious javascript in the victim's browser.
MEDIUM 6.1EPSS 24.7%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 24.7%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
An XSS vulnerability exists in the Jolokia agent version 1.3.7 in the HTTP servlet that allows an attacker to execute malicious javascript in the victim's browser.
- CVSS 3.0
- 6.1 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 24.67% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- jolokia/jolokia
- Source
- cve@mitre.org
References
- https://access.redhat.com/errata/RHSA-2018:2669Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:3817Third Party Advisory
- https://github.com/rhuss/jolokia/commit/5895d5c137c335e6b473e9dcb9baf748851bbc5f#diff-f19898247eddb55de6400489bff748adPatch, Third Party Advisory
- https://jolokia.org/#Security_fixes_with_1.5.0Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:2669Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:3817Third Party Advisory
- https://github.com/rhuss/jolokia/commit/5895d5c137c335e6b473e9dcb9baf748851bbc5f#diff-f19898247eddb55de6400489bff748adPatch, Third Party Advisory
- https://jolokia.org/#Security_fixes_with_1.5.0Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.