Skip to content

[GHSA-c9ff-59g8-m36q] Add finder credit and affected Maven ranges (CVE-2026-84218) - #9645

Open
ByteHackr wants to merge 1 commit into
github:ByteHackr/advisory-improvement-9645from
ByteHackr:cve-2026-84218-credit-GHSA-c9ff-59g8-m36q
Open

ByteHackr wants to merge 1 commit into
github:ByteHackr/advisory-improvement-9645from
ByteHackr:cve-2026-84218-credit-GHSA-c9ff-59g8-m36q

Conversation

@ByteHackr

Copy link
Copy Markdown

Adds a credits entry crediting Sandipan Roy (@ByteHackr) as FINDER for this advisory, and adds the CVE record JSON as a supporting WEB reference.

Public evidence supporting this credit:

The credits structure follows the OSV schema and the convention already used in this repository (e.g. merged PR #7190 and open PR #9446).

Per CONTRIBUTING.md this PR touches exactly one advisory.

@github-actions
github-actions Bot changed the base branch from main to ByteHackr/advisory-improvement-9645 September 20, 2026 19:05
@ByteHackr

Copy link
Copy Markdown
Author

Thanks! Aside from the credit, would the curation team be able to consider this advisory for review (i.e., upgrade it from the NVD mirror entry to a reviewed advisory)? It affects a system/distro package (jolokia), so I understand ecosystem version-range mapping may be limited, but happy to help with any additional information (affected versions, fixed versions, references) that makes the review possible.

@ByteHackr
ByteHackr force-pushed the cve-2026-84218-credit-GHSA-c9ff-59g8-m36q branch from 73547de to cdfef13 Compare September 20, 2026 20:12
@ByteHackr

Copy link
Copy Markdown
Author

Context for the added affected ranges, all verified against upstream sources:

Fix commit: 6ef036d78c3b40602f5e32352e97aed7c0fd5241 — "[Fixes #1049] Deny all target JMX URLs by default if not allowed ... Resolves CVE-2026-84218" — shipped in v2.6.2 (2026-09-02; compare v2.6.2...6ef036d confirms the commit is contained in the tag).

2.x range: org.jolokia:jolokia-service-jsr160 — the JSR-160 proxy handler moved to the reorganized org.jolokia.service.* modules in 2.0.0 (class Jsr160RequestHandler present at tags v2.0.0 through v2.6.1), fixed in 2.6.2.

1.x range: org.jolokia:jolokia-jsr160 — per upstream issue #1049, affected versions are all 1.x from 1.5.0 onward (the CVE-2018-1000130 denylist landed in 1.5.0; class Jsr160RequestDispatcher present at v1.5.0+). No fixed event is declared because no 1.x release contains the fix — only two commits reference #1049 and both are on the 2.x line (search: repo:jolokia/jolokia 1049). If/when a 1.x backport ships, this can be updated.

Happy to adjust if the curation team prefers a different range treatment.

@ByteHackr ByteHackr changed the title Add finder credit for GHSA-c9ff-59g8-m36q [GHSA-c9ff-59g8-m36q] Add finder credit and affected Maven ranges (CVE-2026-84218) Sep 20, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant