Description
A JNDI Injection vulnerability exists in Jolokia agent version 1.3.7 in the proxy mode that allows a remote attacker to run arbitrary Java code on the server.
Remediation
References
https://access.redhat.com/errata/RHSA-2018:2669
https://jolokia.org/#Security_fixes_with_1.5.0
Related Vulnerabilities
CVE-2019-5483 Vulnerability in npm package seneca
CVE-2019-10380 Vulnerability in maven package org.jenkins-ci.plugins:simple-travis-runner
CVE-2015-9238 Vulnerability in npm package secure-compare
CVE-2020-15256 Vulnerability in npm package object-path-set
CVE-2018-16202 Vulnerability in npm package cordova-plugin-ionic-webview