Description
A JNDI Injection vulnerability exists in Jolokia agent version 1.3.7 in the proxy mode that allows a remote attacker to run arbitrary Java code on the server.
Remediation
References
https://access.redhat.com/errata/RHSA-2018:2669
https://jolokia.org/#Security_fixes_with_1.5.0
Related Vulnerabilities
CVE-2021-46708 Vulnerability in maven package com.microfocus.webjars:swagger-ui-dist
CVE-2016-10541 Vulnerability in npm package shell-quote
CVE-2017-16006 Vulnerability in maven package org.webjars:remarkable
CVE-2020-2298 Vulnerability in maven package org.jenkins-ci.plugins:nerrvana-plugin
CVE-2023-37945 Vulnerability in maven package io.jenkins.plugins:miniorange-saml-sp