Description
A JNDI Injection vulnerability exists in Jolokia agent version 1.3.7 in the proxy mode that allows a remote attacker to run arbitrary Java code on the server.
Remediation
References
https://access.redhat.com/errata/RHSA-2018:2669
https://jolokia.org/#Security_fixes_with_1.5.0
Related Vulnerabilities
CVE-2019-16776 Vulnerability in maven package org.webjars.npm:npm
CVE-2019-18212 Vulnerability in maven package org.lsp4xml:org.eclipse.lsp4xml.extensions.emmet
CVE-2021-3223 Vulnerability in npm package node-red-dashboard
CVE-2021-23330 Vulnerability in npm package launchpad
CVE-2018-11804 Vulnerability in maven package org.apache.spark:spark-core_2.10