Description
A JNDI Injection vulnerability exists in Jolokia agent version 1.3.7 in the proxy mode that allows a remote attacker to run arbitrary Java code on the server.
Remediation
References
https://access.redhat.com/errata/RHSA-2018:2669
https://jolokia.org/#Security_fixes_with_1.5.0
Related Vulnerabilities
CVE-2021-23624 Vulnerability in npm package dotty
CVE-2019-17558 Vulnerability in maven package org.apache.solr:solr-velocity
CVE-2019-10744 Vulnerability in maven package org.webjars.npm:lodash
CVE-2018-1320 Vulnerability in maven package org.apache.thrift:libthrift
CVE-2018-18854 Vulnerability in maven package io.spray:spray-json