Jolokia is a niche Java management and monitoring agent that provides remote JMX access and introspection capabilities, with exposure centered on its core agent product and webarchive deployments. The observed vulnerabilities cluster around web-layer input handling and cross-site concerns, including CSRF, input validation bypasses, cross-site scripting, and injection flaws that reflect the agent's HTTP interface and request-processing role. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Jolokia over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-1000130HIGH A JNDI Injection vulnerability exists in Jolokia agent version 1.3.7 in the proxy mode that allows a remote attacker to run arbitrary Java code on the server. | Mar 14, 2018 | 8.1 | 75 | NO | YES |
CVE-2018-1000129MEDIUM An XSS vulnerability exists in the Jolokia agent version 1.3.7 in the HTTP servlet that allows an attacker to execute malicious javascript in the victim's browser. | Mar 14, 2018 | 6.1 | 44 | NO | YES |
CVE-2018-10899HIGH A flaw was found in Jolokia versions from 1.2 to before 1.6.1. Affected versions are vulnerable to a system-wide CSRF. This holds true for properly configured instances with strict | Aug 1, 2019 | 8.8 | 28 | NO | NO |
CVE-2014-0168MEDIUM Cross-site request forgery (CSRF) vulnerability in Jolokia before 1.2.1 allows remote attackers to hijack the authentication of users for requests that execute MBeans methods via a | Oct 6, 2014 | 6.8 | 22 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Jolokia.
Media articles that mention a CVE ID that affects a product developed by Jolokia — matched by CVE ID, not by vendor name.