jolokia kayıtları
jolokia üreticisine ait 4 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-20 Improper Input Validation1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
4 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
54Planlayın | CVE-2018-1000130Kavram kanıtı | A JNDI Injection vulnerability exists in Jolokia agent version 1.3.7 in the proxy mode that allows a remote attacker to run arbitrary Java cjolokia · webarchive agent · CWE-74 | Yüksek8,1 | — | %74,0 | 14 Mar 2018 |
36İzleyin | CVE-2018-10899İstismar yok | A flaw was found in Jolokia versions from 1.2 to before 1.6.1.jolokia · jolokia · CWE-20 | Yüksek8,8 | — | %2,7 | 1 Ağu 2019 |
31İzleyin | CVE-2018-1000129Kavram kanıtı | An XSS vulnerability exists in the Jolokia agent version 1.3.7 in the HTTP servlet that allows an attacker to execute malicious javascript ijolokia · jolokia · CWE-79 | Orta6,1 | — | %24,7 | 14 Mar 2018 |
27İzleyin | CVE-2014-0168İstismar yok | Cross-site request forgery (CSRF) vulnerability in Jolokia before 1.2.1 allows remote attackers to hijack the authentication of users for rejolokia · jolokia · CWE-352 | Orta6,8 | — | %0,7 | 6 Eki 2014 |
- CVE-2018-100013054Planlayın
A JNDI Injection vulnerability exists in Jolokia agent version 1.3.7 in the proxy mode that allows a remote attacker to run arbitrary Java c
YüksekCVSS 8,1Kavram kanıtıEPSS %74jolokia · webarchive agent14 Mar 2018
- CVE-2018-1089936İzleyin
A flaw was found in Jolokia versions from 1.2 to before 1.6.1.
YüksekCVSS 8,8İstismar yokEPSS %3jolokia · jolokia1 Ağu 2019
- CVE-2018-100012931İzleyin
An XSS vulnerability exists in the Jolokia agent version 1.3.7 in the HTTP servlet that allows an attacker to execute malicious javascript i
OrtaCVSS 6,1Kavram kanıtıEPSS %25jolokia · jolokia14 Mar 2018
- CVE-2014-016827İzleyin
Cross-site request forgery (CSRF) vulnerability in Jolokia before 1.2.1 allows remote attackers to hijack the authentication of users for re
OrtaCVSS 6,8İstismar yokEPSS %1jolokia · jolokia6 Eki 2014