Search CVE reports
1 – 7 of 7 results
CVE-2024-46544
Medium priorityIncorrect Default Permissions vulnerability in Apache Tomcat Connectors allows local users to view and modify shared memory containing mod_jk configuration which may lead to information disclosure and/or denial of service. This...
1 affected packages
libapache-mod-jk
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
libapache-mod-jk | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
CVE-2023-41081
Medium prioritySome fixes available 5 of 6
Important: Authentication Bypass CVE-2023-41081 The mod_jk component of Apache Tomcat Connectors in some circumstances, such as when a configuration included "JkOptions +ForwardDirectories" but the configuration did not provide...
1 affected packages
libapache-mod-jk
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
libapache-mod-jk | Not affected | Fixed | Fixed | Fixed | Fixed |
CVE-2018-11759
Medium priorityThe Apache Web Server (httpd) specific code that normalised the requested path before matching it to the URI-worker map in Apache Tomcat JK (mod_jk) Connector 1.2.0 to 1.2.44 did not handle some edge cases correctly. If only a...
1 affected packages
libapache-mod-jk
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
libapache-mod-jk | — | — | Not affected | Not affected | Not affected |
CVE-2016-6808
Medium priorityBuffer overflow in Apache Tomcat Connectors (mod_jk) before 1.2.42.
1 affected packages
libapache-mod-jk
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
libapache-mod-jk | — | — | — | — | Not affected |
CVE-2014-8111
Medium prioritySome fixes available 1 of 4
Apache Tomcat Connectors (mod_jk) before 1.2.41 ignores JkUnmount rules for subtrees of previous JkMount rules, which allows remote attackers to access otherwise restricted artifacts via unspecified vectors.
1 affected packages
libapache-mod-jk
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
libapache-mod-jk | — | — | — | Not affected | Not affected |
CVE-2008-5519
Low prioritySome fixes available 2 of 4
The JK Connector (aka mod_jk) 1.2.0 through 1.2.26 in Apache Tomcat allows remote attackers to obtain sensitive information via an arbitrary request from an HTTP client, in opportunistic circumstances involving (1) a request from...
1 affected packages
libapache-mod-jk
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
libapache-mod-jk | — | — | — | — | — |
CVE-2007-1860
Unknown prioritySome fixes available 4 of 6
mod_jk in Apache Tomcat JK Web Server Connector 1.2.x before 1.2.23 decodes request URLs within the Apache HTTP Server before passing the URL to Tomcat, which allows remote attackers to access protected pages via a crafted prefix...
1 affected packages
libapache-mod-jk
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
libapache-mod-jk | — | — | — | — | — |