A flaw was found in Jolokia versions from 1.2 to before 1.6.1. Affected versions are vulnerable to a system-wide CSRF. This holds true for properly configured instances with strict checking for origin and referrer headers. This could result in a Remote Code Execution attack.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| org.jolokia:jolokia-core(Maven) | 1.2 | 1.6.1 | N/A |
CVSS Metrics