Description
A JNDI Injection vulnerability exists in Jolokia agent version 1.3.7 in the proxy mode that allows a remote attacker to run arbitrary Java code on the server.
Remediation
References
https://jolokia.org/#Security_fixes_with_1.5.0
https://access.redhat.com/errata/RHSA-2018:2669
Related Vulnerabilities
CVE-2022-24839 Vulnerability in maven package net.sourceforge.nekohtml:nekohtml
CVE-2018-19048 Vulnerability in npm package simditor
CVE-2021-25329 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core
CVE-2023-44487 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core