jolokia: JMX proxy mode vulnerable to remote code execution
Published Mar 14, 2018
8.1
HIGHCVSS 3.0
EPSS 73.98%
Description
A JNDI Injection vulnerability exists in Jolokia agent version 1.3.7 in the proxy mode that allows a remote attacker to run arbitrary Java code on the server.
Affected products
No data.
- 1.3.7
No data.
Red Hat JBoss Fuse 7
jolokia-core
Fixed · RHSA-2018:2669
JBoss Developer Studio 11
jolokia-core
Not affected
Red Hat AMQ Broker 7
jolokia-core
Affected
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo)
opendaylight
Not affected
Red Hat JBoss A-MQ 6
jolokia-core
Will not fix
Red Hat JBoss Data Virtualization 6
jolokia-client-java
Out of support scope
Red Hat JBoss Fuse 6
jolokia-core
Will not fix
Red Hat JBoss Fuse Integration Service 2
jolokia-core
Affected
Red Hat OpenStack Platform 10 (Newton)
opendaylight
Will not fix
Red Hat OpenStack Platform 11 (Ocata)
opendaylight
Not affected
Red Hat OpenStack Platform 12 (Pike)
opendaylight
Will not fix
Red Hat OpenStack Platform 13 (Queens)
opendaylight
Will not fix
Red Hat OpenStack Platform 8 (Liberty)
opendaylight
Not affected
Red Hat OpenStack Platform 9 (Mitaka)
opendaylight
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat JBoss Fuse 7 | jolokia-core | Fixed | RHSA-2018:2669 |
| JBoss Developer Studio 11 | jolokia-core | Not affected | n/a |
| Red Hat AMQ Broker 7 | jolokia-core | Affected | n/a |
| Red Hat Enterprise Linux OpenStack Platform 7 (Kilo) | opendaylight | Not affected | n/a |
| Red Hat JBoss A-MQ 6 | jolokia-core | Will not fix | n/a |
| Red Hat JBoss Data Virtualization 6 | jolokia-client-java | Out of support scope | n/a |
| Red Hat JBoss Fuse 6 | jolokia-core | Will not fix | n/a |
| Red Hat JBoss Fuse Integration Service 2 | jolokia-core | Affected | n/a |
| Red Hat OpenStack Platform 10 (Newton) | opendaylight | Will not fix | n/a |
| Red Hat OpenStack Platform 11 (Ocata) | opendaylight | Not affected | n/a |
| Red Hat OpenStack Platform 12 (Pike) | opendaylight | Will not fix | n/a |
| Red Hat OpenStack Platform 13 (Queens) | opendaylight | Will not fix | n/a |
| Red Hat OpenStack Platform 8 (Liberty) | opendaylight | Not affected | n/a |
| Red Hat OpenStack Platform 9 (Mitaka) | opendaylight | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
For Red Hat OpenStack Platform, although the affected code is present in shipped packages, proxy mode is not enabled by default and the affected code is not used in any supported configuration of Red Hat OpenStack Platform. For this reason, the RHOSP impact as been reduced to Low and this issue is not currently planned to be addressed in future updates.
References (11)
- https://access.redhat.com/errata/RHSA-2018:2669 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2018-1000130 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1559316 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-5177 Advisory
- https://github.com/advisories/GHSA-rhqj-4pp8-vvgf Advisory
- https://github.com/rhuss/jolokia/commit/1b360b8889f0ed51165a8d1ac55dd8e0aa2dfd4a
- https://github.com/rhuss/jolokia/commit/fd7b93da30c61a45bac10d8b311f1b79a74910f5
- https://github.com/rhuss/jolokia/releases/tag/v1.5.0
- https://jolokia.org/#Security_fixes_with_1.5.0 x_refsource_CONFIRMRelease NotesVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-1000130
- https://www.cve.org/CVERecord?id=CVE-2018-1000130
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2018:2669 | vendor-advisoryx_refsource_REDHATThird Party Advisory | |
| https://access.redhat.com/security/cve/CVE-2018-1000130 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1559316 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-5177 | Advisory | |
| https://github.com/advisories/GHSA-rhqj-4pp8-vvgf | Advisory | |
| https://github.com/rhuss/jolokia/commit/1b360b8889f0ed51165a8d1ac55dd8e0aa2dfd4a | ||
| https://github.com/rhuss/jolokia/commit/fd7b93da30c61a45bac10d8b311f1b79a74910f5 | ||
| https://github.com/rhuss/jolokia/releases/tag/v1.5.0 | ||
| https://jolokia.org/#Security_fixes_with_1.5.0 | x_refsource_CONFIRMRelease NotesVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2018-1000130 | ||
| https://www.cve.org/CVERecord?id=CVE-2018-1000130 |
Change history (0)
No recorded changes yet.