PT-2023-5210 · Apache+5 · Apache Tomcat Connectors+5

Karl Von Randow

·

Publicado

2023-09-11

·

Atualizado

2025-01-14

·

CVE-2023-41081

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache Tomcat Connectors versions 1.2.0 through 1.2.48
Description The mod jk component of Apache Tomcat Connectors is affected by an issue where, in certain circumstances, such as when a configuration includes "JkOptions +ForwardDirectories" but does not provide explicit mounts for all possible proxied requests, mod jk would use an implicit mapping and map the request to the first defined worker. This could result in the unintended exposure of the status worker and/or bypass security constraints configured in httpd. The issue is resolved in version 1.2.49, where the implicit mapping functionality has been removed, and all mappings must now be via explicit configuration.
Recommendations Upgrade to version 1.2.49, which fixes the issue.

Correção

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALSA-2024:2387
BDU:2023-05818
CVE-2023-41081
DLA-3580-1
INFSA-2024_2387
MGASA-2024-0130
OPENSUSE-SU-2025_0102-1
RHSA-2023:7625
RHSA-2024:2387
RHSA-2024_2387
SUSE-SU-2024:1198-1
SUSE-SU-2024_1198-1
SUSE-SU-2025:0102-1
SUSE-SU-2025_0102-1
USN-6826-1

Produtos afetados

Almalinux
Apache Tomcat Connectors
Linuxmint
Red Hat
Suse
Ubuntu