Back

HIGH

jolokia: JMX proxy mode vulnerable to remote code execution

Published Mar 14, 2018

Description

A JNDI Injection vulnerability exists in Jolokia agent version 1.3.7 in the proxy mode that allows a remote attacker to run arbitrary Java code on the server.

Affected products

Remediation

Red Hat statement

For Red Hat OpenStack Platform, although the affected code is present in shipped packages, proxy mode is not enabled by default and the affected code is not used in any supported configuration of Red Hat OpenStack Platform. For this reason, the RHOSP impact as been reduced to Low and this issue is not currently planned to be addressed in future updates.

Weaknesses (2)

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Mar 14, 2018
Updated Aug 5, 2024
Reserved Mar 14, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Feb 8, 2018
ENISA EUVD
Assigner mitre
Published Mar 14, 2018
Updated Aug 5, 2024
Exploited since n/a
EUVD-2022-5177 GHSA-RHQJ-4PP8-VVGF