jolokia: system-wide CSRF that could lead to Remote Code Execution
Published Aug 1, 2019
8.8
HIGHCVSS 3.0
EPSS 2.67%
Description
A flaw was found in Jolokia versions from 1.2 to before 1.6.1. Affected versions are vulnerable to a system-wide CSRF. This holds true for properly configured instances with strict checking for origin and referrer headers. This could result in a Remote Code Execution attack.
Affected products
-
- Version 1.6.1StatusaffectedConstraints-
- Version
No data.
Red Hat Fuse 6.3
jolokia-core
Fixed · RHSA-2019:2804
Red Hat Fuse 6.3
jolokia-core
Fixed · RHSA-2019:2804
Red Hat Fuse 7.4.0
jolokia-core
Fixed · RHSA-2019:2413
JBoss Developer Studio 11
jolokia-core
Out of support scope
Red Hat AMQ Broker 7
jolokia-core
Affected
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo)
opendaylight
Will not fix
Red Hat JBoss Data Virtualization 6
jolokia-core
Not affected
Red Hat OpenStack Platform 10 (Newton)
opendaylight
Will not fix
Red Hat OpenStack Platform 12 (Pike)
opendaylight
Will not fix
Red Hat OpenStack Platform 13 (Queens)
opendaylight
Fix deferred
Red Hat OpenStack Platform 8 (Liberty)
opendaylight
Will not fix
Red Hat OpenStack Platform 9 (Mitaka)
opendaylight
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Fuse 6.3 | jolokia-core | Fixed | RHSA-2019:2804 |
| Red Hat Fuse 6.3 | jolokia-core | Fixed | RHSA-2019:2804 |
| Red Hat Fuse 7.4.0 | jolokia-core | Fixed | RHSA-2019:2413 |
| JBoss Developer Studio 11 | jolokia-core | Out of support scope | n/a |
| Red Hat AMQ Broker 7 | jolokia-core | Affected | n/a |
| Red Hat Enterprise Linux OpenStack Platform 7 (Kilo) | opendaylight | Will not fix | n/a |
| Red Hat JBoss Data Virtualization 6 | jolokia-core | Not affected | n/a |
| Red Hat OpenStack Platform 10 (Newton) | opendaylight | Will not fix | n/a |
| Red Hat OpenStack Platform 12 (Pike) | opendaylight | Will not fix | n/a |
| Red Hat OpenStack Platform 13 (Queens) | opendaylight | Fix deferred | n/a |
| Red Hat OpenStack Platform 8 (Liberty) | opendaylight | Will not fix | n/a |
| Red Hat OpenStack Platform 9 (Mitaka) | opendaylight | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
In Red Hat OpenStack Platform, jolokia is not enabled by default and, when enabled, the jolokia endpoints do not rely on CORS for security. Therefore, the impact has been reduced to Low and no updates will be provided at this time for the RHOSP jolokia package.
References (24)
- https://access.redhat.com/errata/RHSA-2019:2413 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2804 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2018-10899 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1601037 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10899 x_refsource_CONFIRMIssue TrackingThird Party Advisory
- https://github.com/advisories/GHSA-xcxf-7q4p-cj26 Advisory
- https://jolokia.org/#Minor_updates_coming_with_1.6.1
- https://jolokia.org/changes-report.html#a1.6.1 x_refsource_CONFIRMRelease NotesVendor Advisory
- https://lists.apache.org/thread.html/1392fbebb4fbbec379a40d16e1288fe1e4c0289d257e5206051a3793%40%3Cissues.activemq.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/1392fbebb4fbbec379a40d16e1288fe1e4c0289d257e5206051a3793@%3Cissues.activemq.apache.org%3E
- https://lists.apache.org/thread.html/r46f6dbc029f49e1f638c6eb82accb94b7f990d818cb3b3bc0007dd0a%40%3Cissues.activemq.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r46f6dbc029f49e1f638c6eb82accb94b7f990d818cb3b3bc0007dd0a@%3Cissues.activemq.apache.org%3E
- https://lists.apache.org/thread.html/r64701caec91c43efd7416d6bddef88447371101e00e8562741ede262%40%3Cissues.activemq.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r64701caec91c43efd7416d6bddef88447371101e00e8562741ede262@%3Cissues.activemq.apache.org%3E
- https://lists.apache.org/thread.html/r67cdc50af9caf89c9ebe1bde08393a343dcd89edba1c63677f68f43b%40%3Cissues.activemq.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r67cdc50af9caf89c9ebe1bde08393a343dcd89edba1c63677f68f43b@%3Cissues.activemq.apache.org%3E
- https://lists.apache.org/thread.html/rc169dac018d07e8ddf2a3bb2fd1efc6cbda4f83f1bbf7a8c798e7f4f%40%3Cissues.activemq.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rc169dac018d07e8ddf2a3bb2fd1efc6cbda4f83f1bbf7a8c798e7f4f@%3Cissues.activemq.apache.org%3E
- https://lists.apache.org/thread.html/rdb0a59d7851e721b75beea13d6488e345a3e2735838e89d9269d7d32%40%3Cissues.activemq.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rdb0a59d7851e721b75beea13d6488e345a3e2735838e89d9269d7d32@%3Cissues.activemq.apache.org%3E
- https://lists.apache.org/thread.html/rf33ffbba619a4281ce592a6ed259c07a557aefb4975619d83c4122ea%40%3Cissues.activemq.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rf33ffbba619a4281ce592a6ed259c07a557aefb4975619d83c4122ea@%3Cissues.activemq.apache.org%3E
- https://nvd.nist.gov/vuln/detail/CVE-2018-10899
- https://www.cve.org/CVERecord?id=CVE-2018-10899
Change history (0)
No recorded changes yet.