CVE-2018-1000129

Scores

EPSS

0.768medium76.8%
0%20%40%60%80%100%

Percentile: 76.8%

CVSS

6.1medium3.x
0246810

CVSS Score: 6.1/10

All CVSS Scores

CVSS 3.x
6.1

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CVSS 2.0
4.3

Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Description

An XSS vulnerability exists in the Jolokia agent version 1.3.7 in the HTTP servlet that allows an attacker to execute malicious javascript in the victim’s browser.

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

nvd

CWEs

CWE-79

Exploits

Exploit ID: CVE-2018-1000129

Source: github-poc

URL: https://github.com/shoucheng3/rhuss__jolokia_CVE-2018-1000129_1-4-0

Recommendations

Source: nvd

Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on.
Installation instructions are located in the download section of the customer portal.
The References section of this erratum contains a download link (you must log in to download the update).

URL: https://access.redhat.com/errata/RHSA-2018:3817

Vulnerable Software (1)

Type: Configuration

Vendor: *

Product: jolokia

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:jolokia:jolokia:1.3.7:*:*:*:*:*:*:*",      "vulnerable": true    }  ],  "operator": "OR"}

Source: nvd

End of list