PT-2018-2515 · Apache+1 · Apache Tomcat Jk (Mod Jk) Connector+1

Publicado

2018-06-05

·

Atualizado

2024-06-15

·

CVE-2018-11759

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache Tomcat JK (mod jk) Connector versions 1.2.0 through 1.2.44
Description The issue is related to the normalization of requested paths in the Apache Tomcat JK (mod jk) Connector, which did not handle some edge cases correctly. This could allow a specially constructed request to expose application functionality through the reverse proxy that was not intended for clients accessing the application via the reverse proxy. Additionally, in some configurations, it was possible for a specially constructed request to bypass the access controls configured in the httpd server. The vulnerability is related to incorrect handling of boundary conditions, specifically the filtering of the ';' symbol, during the normalization of the requested path and its mapping to the URI-worker array in mod jk.
Recommendations For versions 1.2.0 through 1.2.44, consider disabling the mod jk connector until a patch is available to prevent potential exploitation. Restrict access to the reverse proxy to minimize the risk of bypassing access controls. Avoid using specially constructed requests that could expose application functionality or bypass access controls. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2019-00886
CVE-2018-11759
DLA-1609-1
DSA-4357-1
OPENSUSE-SU-2018_4032-1
OPENSUSE-SU-2023_4513-1
OPENSUSE-SU-2024:10625-1
RHSA-2019:0367
SUSE-SU-2018:3963-2
SUSE-SU-2018:3969-1
SUSE-SU-2018:3970-1
SUSE-SU-2018_3963-1
SUSE-SU-2018_3963-2
SUSE-SU-2018_3969-1
SUSE-SU-2018_3970-1
SUSE-SU-2023:4513-1
SUSE-SU-2023_4513-1

Produtos afetados

Apache Tomcat Jk (Mod Jk) Connector
Suse