Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-41081
HistorySep 13, 2023 - 12:00 a.m.

CVE-2023-41081

2023-09-1300:00:00
ubuntu.com
ubuntu.com
22
cve-2023-41081
mod_jk
apache tomcat connectors
security bypass
upgrade
implicit mapping
status worker

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.002

Percentile

61.9%

Important: Authentication Bypass CVE-2023-41081 The mod_jk component of
Apache Tomcat Connectors in some circumstances, such as when a
configuration included “JkOptions +ForwardDirectories” but the
configuration did not provide explicit mounts for all possible proxied
requests, mod_jk would use an implicit mapping and map the request to the
first defined worker. Such an implicit mapping could result in the
unintended exposure of the status worker and/or bypass security constraints
configured in httpd. As of JK 1.2.49, the implicit mapping functionality
has been removed and all mappings must now be via explicit configuration.
Only mod_jk is affected by this issue. The ISAPI redirector is not
affected. This issue affects Apache Tomcat Connectors (mod_jk only): from
1.2.0 through 1.2.48. Users are recommended to upgrade to version 1.2.49,
which fixes the issue. History 2023-09-13 Original advisory 2023-09-28
Updated summary

OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchlibapache-mod-jk< 1:1.2.43-1ubuntu0.1~esm1UNKNOWN
ubuntu20.04noarchlibapache-mod-jk< 1:1.2.46-1ubuntu0.1UNKNOWN
ubuntu22.04noarchlibapache-mod-jk< 1:1.2.48-1ubuntu0.1UNKNOWN
ubuntu23.10noarchlibapache-mod-jk< 1:1.2.48-2ubuntu0.1UNKNOWN
ubuntu16.04noarchlibapache-mod-jk< 1:1.2.41-1ubuntu0.1~esm1UNKNOWN

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.002

Percentile

61.9%