Cross-Site Request Forgery in Jolokia
High severity
GitHub Reviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Jan 27, 2023
Description
Published by the National Vulnerability Database
Aug 1, 2019
Published to the GitHub Advisory Database
May 24, 2022
Reviewed
Jun 29, 2022
Last updated
Jan 27, 2023
A flaw was found in Jolokia versions from 1.2 to before 1.6.1. Affected versions are vulnerable to a system-wide CSRF. This holds true for properly configured instances with strict checking for origin and referrer headers. This could result in a Remote Code Execution attack.
References