CVE-2018-1000129: Jolokia

Medium severity, CVSS 6.1. EPSS: 24.7% chance of exploitation in the next 30 days.

An XSS vulnerability exists in the Jolokia agent version 1.3.7 in the HTTP servlet that allows an attacker to execute malicious javascript in the victim's browser.

Affected products

  • Jolokia Jolokia: version 1.3.7 only

Published 2018-03-14. Last modified 2026-06-17.