CVE-2018-10899: Cross-Site Request Forgery (CSRF)
(updated )
A flaw was found in Jolokia which is vulnerable to a system-wide CSRF. This holds true for properly configured instances with strict checking for origin and referrer headers. This could result in a Remote Code Execution attack.
References
Detect and mitigate CVE-2018-10899 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →