CVE-2018-1000129

Description

An XSS vulnerability exists in the Jolokia agent version 1.3.7 in the HTTP servlet that allows an attacker to execute malicious javascript in the victims browser.

Risk Information

Base Score
6.1
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS Score
Exploitation Probability
67.423

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2018-1000129,CVE-2018-1000130 are fixed in Jolokia-jolokia-core 1.5.0Windows
Vulnerabilities CVE-2018-1000129,CVE-2018-1000130 are fixed in Jolokia-jolokia-core for Linux 1.5.0Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234