Jolokia 的 JSR-160 代理功能中存在一个缺陷:由于对客户端可控的 JMX 服务 URL 验证不足,导致用于缓解 CVE-2018-1000130 的黑名单机制可被绕过。该代理从 Jolokia 的 POST 请求中获取 值,并将其传递给 和 以建立远程 JMX 连接。现有的黑名单仅拒绝匹配 的 URL,攻击者可以使用其他有效的 JMX 服务 URL 形式来绕过,例如使用 协议或带有非空 JMX 主机分量的 LDAP URL。这些 URL 会被接受为有效的 对象,并可能导致 Jolokia agent
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat build of Apache Camel 4 for Quarkus 3 | - |
cpe:/a:redhat:camel_quarkus:3
|
|
| Red Hat | Red Hat build of Apache Camel for Spring Boot 4 | - |
cpe:/a:redhat:camel_spring_boot:4
|
|
| Red Hat | Red Hat Fuse 7 | - |
cpe:/a:redhat:jboss_fuse:7
|
|
| Red Hat | Red Hat Satellite 6 | - |
cpe:/a:redhat:satellite:6
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-11873 | 6.5 MEDIUM | Pki-core: dogtag-pki: empty request to dogtag /ca/rest/certrequests causes http 500, java |
| CVE-2026-53682 | 5.3 MEDIUM | Pki-core: dogtag-pki: unauthenticated dogtag ca rest api exposes security domain hosts |
No comments yet