org.jolokia:jolokia-core@1.1.5 vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the org.jolokia:jolokia-core package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • H
Arbitrary Code Execution

org.jolokia:jolokia-core is a fresh way to access JMX MBeans remotely.

Affected versions oft his package are vulnerable to Arbitrary Code Execution in the proxy mode. It allows a remote attacker to run arbitrary Java code on the server.

How to fix Arbitrary Code Execution?

Upgrade org.jolokia:jolokia-core to version 1.5.0 or higher.

[,1.5.0)
  • M
Cross-site Scripting (XSS)

org.jolokia:jolokia-core is a fresh way to access JMX MBeans remotely.

Affected versions of this package are vulnerable to Cross-site Scripting (XSS) in the HTTP servlet. It allows an attacker to execute malicious javascript in the victim's browser.

How to fix Cross-site Scripting (XSS)?

Upgrade org.jolokia:jolokia-core to version 1.5.0 or higher.

[,1.5.0)
  • M
Cross-site Request Forgery (CSRF)

org.jolokia:jolokia-core Cross-site request forgery (CSRF) vulnerability in Jolokia before 1.2.1 allows remote attackers to hijack the authentication of users for requests that execute MBeans methods via a crafted web page.

[,1.2.1)