8.1

CVE-2026-84218

Org.jolokia/jolokia-core: incomplete jndi denylist in jolokia jsr-160 proxy (bypass of cve-2018-1000130 fix)

A flaw was found in Jolokia's JSR-160 proxy functionality where insufficient validation of client-controlled JMX service URLs allows a bypass of the denylist introduced to mitigate CVE-2018-1000130. The proxy accepts a `target.url` value from a Jolokia POST request and passes it to `JMXServiceURL` and `JMXConnectorFactory` for establishing the remote JMX connection. The existing denylist only rejects URLs matching `service:jmx:rmi:///jndi/ldap:.*`, which can be bypassed using alternative valid JMX service URL forms, including `ldaps://` schemes or LDAP URLs with a non-empty JMX host component. These URLs are accepted as valid `JMXServiceURL` objects and can cause the Jolokia agent JVM to perform a JNDI lookup against an attacker-controlled LDAP endpoint. This can result in server-side request forgery (SSRF), forwarding of supplied JMX credentials to the remote endpoint, and potentially remote code execution depending on the classes and configuration available in the target JVM.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerRed Hat
≫
Produkt Red Hat AMQ Broker 7
Default Statusaffected
HerstellerRed Hat
≫
Produkt Red Hat build of Apache Camel 4 for Quarkus 3
Default Statusunknown
HerstellerRed Hat
≫
Produkt Red Hat build of Apache Camel 4 for Quarkus 3
Default Statusunknown
HerstellerRed Hat
≫
Produkt Red Hat build of Apache Camel for Spring Boot 4
Default Statusunknown
HerstellerRed Hat
≫
Produkt Red Hat build of Apache Camel for Spring Boot 4
Default Statusunknown
HerstellerRed Hat
≫
Produkt Red Hat Fuse 7
Default Statusunknown
HerstellerRed Hat
≫
Produkt Red Hat Satellite 6
Default Statusunaffected
HerstellerRed Hat
≫
Produkt Red Hat Satellite 6
Default Statusunaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.88% 0.567
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
RedHat 8.1 2.2 5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-184 Incomplete List of Disallowed Inputs

The product implements a protection mechanism that relies on a list of inputs (or properties of inputs) that are not allowed by policy or otherwise require other action to neutralize before additional processing takes place, but the list is incomplete.

https://access.redhat.com/security/cve/CVE-2026-84218
https://bugzilla.redhat.com/show_bug.cgi?id=2526752
https://github.com/jolokia/jolokia/issues/1049
https://github.com/advisories/GHSA-c9ff-59g8-m36q
https://jolokia.org/#jolokia_2_6_2_released_with_security_fixes