6.8
CVSSv2

CVE-2014-0168

Published: 06/10/2014 Updated: 07/10/2014
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site request forgery (CSRF) vulnerability in Jolokia prior to 1.2.1 allows remote malicious users to hijack the authentication of users for requests that execute MBeans methods via a crafted web page.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

jolokia jolokia 1.0.2

jolokia jolokia 1.0.1

jolokia jolokia 1.0.0

jolokia jolokia 1.1.5

jolokia jolokia 1.1.0

jolokia jolokia 1.0.5

jolokia jolokia 1.0.3

jolokia jolokia 1.1.4

jolokia jolokia 1.1.3

jolokia jolokia 1.1.2

jolokia jolokia 1.1.1

jolokia jolokia

jolokia jolokia 1.0.6

jolokia jolokia 1.0.4

Vendor Advisories

It was found that Jolokia was vulnerable to Cross-Site Request Forgery (CSRF) attacks A remote attacker could provide a specially crafted web page that, when visited by a user logged in to Jolokia, could allow the attacker to execute arbitrary methods on MBeans exposed via JMX ...