PT-2023-5210 · Apache+5 · Apache Tomcat Connectors+5
Karl Von Randow
·
Published
2023-09-11
·
Updated
2025-01-14
·
CVE-2023-41081
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Apache Tomcat Connectors versions 1.2.0 through 1.2.48
Description
The mod jk component of Apache Tomcat Connectors is affected by an issue where, in certain circumstances, such as when a configuration includes "JkOptions +ForwardDirectories" but does not provide explicit mounts for all possible proxied requests, mod jk would use an implicit mapping and map the request to the first defined worker. This could result in the unintended exposure of the status worker and/or bypass security constraints configured in httpd. The issue is resolved in version 1.2.49, where the implicit mapping functionality has been removed, and all mappings must now be via explicit configuration.
Recommendations
Upgrade to version 1.2.49, which fixes the issue.
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Almalinux
Apache Tomcat Connectors
Linuxmint
Red Hat
Suse
Ubuntu