A JNDI Injection vulnerability exists in Jolokia agent version 1.3.7 in the proxy mode that allows a remote attacker to run arbitrary Java code on the server.
{
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2022-06-30T18:22:46Z",
"cwe_ids": [
"CWE-74"
],
"nvd_published_at": "2018-03-14T13:29:00Z"
}