Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:20964
HistoryAug 02, 2019 - 5:41 a.m.

Cross-site Request Forgery (CSRF)

2019-08-0205:41:55
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11

0.004 Low

EPSS

Percentile

72.2%

jolokia is vulnerable to cross-site request forgery (CSRF). The backend manager does not properly handle the strict checking for origin and referrer header, causing a system-wide CSRF which subsequently allows a remote code execution.

References