
Jolokia endpoints: JNDI RCE and heap dumps
A full lab build and exploitation walkthrough for exposed Jolokia JMX endpoints: reflected XSS (CVE-2018-1000129), JNDI remote code execution via a rogue LDAP server (CVE-2018-1000130), and dumping the Java heap to recover credentials.