Jolokia 1.3.7 is vulnerable to cross-site scripting in the HTTP servlet and allows an attacker to execute malicious JavaScript in the victim’s browser.
View the template here CVE-2018-1000129.yaml
References:
https://jolokia.org/#Security_fixes_with_1.5.0