Description
A JNDI Injection vulnerability exists in Jolokia agent version 1.3.7 in the proxy mode that allows a remote attacker to run arbitrary Java code on the server.
Remediation
References
https://access.redhat.com/errata/RHSA-2018:2669
https://jolokia.org/#Security_fixes_with_1.5.0
Related Vulnerabilities
CVE-2022-43412 Vulnerability in maven package org.jenkins-ci.plugins:generic-webhook-trigger
CVE-2023-26155 Vulnerability in npm package node-qpdf
CVE-2018-3787 Vulnerability in npm package simplehttpserver
CVE-2020-9281 Vulnerability in npm package ckeditor4-dev
CVE-2020-2153 Vulnerability in maven package org.jenkins-ci.plugins:backlog