PT-2018-2515 · Apache+1 · Apache Tomcat Jk (Mod Jk) Connector+1

Published

2018-06-05

·

Updated

2024-06-15

·

CVE-2018-11759

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache Tomcat JK (mod jk) Connector versions 1.2.0 through 1.2.44
Description The issue is related to the normalization of requested paths in the Apache Tomcat JK (mod jk) Connector, which did not handle some edge cases correctly. This could allow a specially constructed request to expose application functionality through the reverse proxy that was not intended for clients accessing the application via the reverse proxy. Additionally, in some configurations, it was possible for a specially constructed request to bypass the access controls configured in the httpd server. The vulnerability is related to incorrect handling of boundary conditions, specifically the filtering of the ';' symbol, during the normalization of the requested path and its mapping to the URI-worker array in mod jk.
Recommendations For versions 1.2.0 through 1.2.44, consider disabling the mod jk connector until a patch is available to prevent potential exploitation. Restrict access to the reverse proxy to minimize the risk of bypassing access controls. Avoid using specially constructed requests that could expose application functionality or bypass access controls. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-00886
CVE-2018-11759
DLA-1609-1
DSA-4357-1
OPENSUSE-SU-2018_4032-1
OPENSUSE-SU-2023_4513-1
OPENSUSE-SU-2024:10625-1
RHSA-2019:0367
SUSE-SU-2018:3963-2
SUSE-SU-2018:3969-1
SUSE-SU-2018:3970-1
SUSE-SU-2018_3963-1
SUSE-SU-2018_3963-2
SUSE-SU-2018_3969-1
SUSE-SU-2018_3970-1
SUSE-SU-2023:4513-1
SUSE-SU-2023_4513-1

Affected Products

Apache Tomcat Jk (Mod Jk) Connector
Suse