PT-2012-3103 · Red Hat · Mod Cluster

David Jorm

·

Published

2012-10-22

·

Updated

2022-05-17

·

CVE-2012-1154

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions mod cluster versions 1.0.10 through 1.0.10 CP02 mod cluster versions 1.1.x through 1.1.3
Description The issue allows remote attackers to bypass access restrictions and gain access to applications deployed on the root context via unspecified vectors when the "ROOT" is set to excludedContexts.
Recommendations For mod cluster versions 1.0.10 through 1.0.10 CP02, update to version 1.0.10 CP03 or later. For mod cluster versions 1.1.x through 1.1.3, update to version 1.1.4 or later.

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-1154
GHSA-V2FP-H4QX-X3R6
RHSA-2012:1052
RHSA-2012:1053
RHSA-2012:1166

Affected Products

Mod Cluster