PT-2018-2515 · Apache+1 · Apache Tomcat Jk (Mod Jk) Connector+1
Published
2018-06-05
·
Updated
2024-06-15
·
CVE-2018-11759
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Apache Tomcat JK (mod jk) Connector versions 1.2.0 through 1.2.44
Description
The issue is related to the normalization of requested paths in the Apache Tomcat JK (mod jk) Connector, which did not handle some edge cases correctly. This could allow a specially constructed request to expose application functionality through the reverse proxy that was not intended for clients accessing the application via the reverse proxy. Additionally, in some configurations, it was possible for a specially constructed request to bypass the access controls configured in the httpd server. The vulnerability is related to incorrect handling of boundary conditions, specifically the filtering of the ';' symbol, during the normalization of the requested path and its mapping to the URI-worker array in mod jk.
Recommendations
For versions 1.2.0 through 1.2.44, consider disabling the mod jk connector until a patch is available to prevent potential exploitation. Restrict access to the reverse proxy to minimize the risk of bypassing access controls. Avoid using specially constructed requests that could expose application functionality or bypass access controls. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Tomcat Jk (Mod Jk) Connector
Suse