Vulnerability Description
A flaw was found in Jolokia versions from 1.2 to before 1.6.1. Affected versions are vulnerable to a system-wide CSRF. This holds true for properly configured instances with strict checking for origin and referrer headers. This could result in a Remote Code Execution attack.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Jolokia | Jolokia | >= 1.2.0, < 1.6.1 |
| Redhat | Openstack | 13 |
Related Weaknesses (CWE)
References
- https://access.redhat.com/errata/RHSA-2019:2413Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2804
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10899Issue TrackingThird Party Advisory
- https://jolokia.org/changes-report.html#a1.6.1Release NotesVendor Advisory
- https://lists.apache.org/thread.html/1392fbebb4fbbec379a40d16e1288fe1e4c0289d257
- https://lists.apache.org/thread.html/r46f6dbc029f49e1f638c6eb82accb94b7f990d818c
- https://lists.apache.org/thread.html/r64701caec91c43efd7416d6bddef88447371101e00
- https://lists.apache.org/thread.html/r67cdc50af9caf89c9ebe1bde08393a343dcd89edba
- https://lists.apache.org/thread.html/rc169dac018d07e8ddf2a3bb2fd1efc6cbda4f83f1b
- https://lists.apache.org/thread.html/rdb0a59d7851e721b75beea13d6488e345a3e273583
- https://lists.apache.org/thread.html/rf33ffbba619a4281ce592a6ed259c07a557aefb497
- https://access.redhat.com/errata/RHSA-2019:2413Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2804
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10899Issue TrackingThird Party Advisory
- https://jolokia.org/changes-report.html#a1.6.1Release NotesVendor Advisory
FAQ
What is CVE-2018-10899?
CVE-2018-10899 is a vulnerability with a CVSS score of 8.1 (HIGH). A flaw was found in Jolokia versions from 1.2 to before 1.6.1. Affected versions are vulnerable to a system-wide CSRF. This holds true for properly configured instances with strict checking for origin...
How severe is CVE-2018-10899?
CVE-2018-10899 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-10899?
Check the references section above for vendor advisories and patch information. Affected products include: Jolokia Jolokia, Redhat Openstack.