CVE-2014-8111

Description

Apache Tomcat Connectors (mod_jk) before 1.2.41 ignores JkUnmount rules for subtrees of previous JkMount rules, which allows remote attackers to access otherwise restricted artifacts via unspecified vectors.

Risk Information

Base Score
7.5
MODERATE
Vector
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
3.739

Associated Vulnerability

VulnerabilityOS Platform
SUSE-SU-2015:1851-1(SUSE Linux Enterprise Server 12 ) apache2-2.4.10-14.10.1.x86_64.rpmLinux
SUSE-SU-2015:1851-1(SUSE Linux Enterprise Server 12 ) apache2-debuginfo-2.4.10-14.10.1.x86_64.rpmLinux
SUSE-SU-2015:1851-1(SUSE Linux Enterprise Server 12 ) apache2-debugsource-2.4.10-14.10.1.x86_64.rpmLinux
SUSE-SU-2015:1851-1(SUSE Linux Enterprise Server 12 ) apache2-doc-2.4.10-14.10.1.noarch.rpmLinux
SUSE-SU-2015:1851-1(SUSE Linux Enterprise Server 12 ) apache2-example-pages-2.4.10-14.10.1.x86_64.rpmLinux
SUSE-SU-2015:1851-1(SUSE Linux Enterprise Server 12 ) apache2-mod_auth_kerb-5.4-2.4.1.x86_64.rpmLinux
SUSE-SU-2015:1851-1(SUSE Linux Enterprise Server 12 ) apache2-mod_auth_kerb-debuginfo-5.4-2.4.1.x86_64.rpmLinux
SUSE-SU-2015:1851-1(SUSE Linux Enterprise Server 12 ) apache2-mod_auth_kerb-debugsource-5.4-2.4.1.x86_64.rpmLinux
SUSE-SU-2015:1851-1(SUSE Linux Enterprise Server 12 ) apache2-mod_jk-1.2.40-2.6.1.x86_64.rpmLinux
SUSE-SU-2015:1851-1(SUSE Linux Enterprise Server 12 ) apache2-mod_jk-debuginfo-1.2.40-2.6.1.x86_64.rpmLinux
SUSE-SU-2015:1851-1(SUSE Linux Enterprise Server 12 ) apache2-mod_jk-debugsource-1.2.40-2.6.1.x86_64.rpmLinux
SUSE-SU-2015:1851-1(SUSE Linux Enterprise Server 12 ) apache2-mod_security2-2.8.0-3.4.1.x86_64.rpmLinux
SUSE-SU-2015:1851-1(SUSE Linux Enterprise Server 12 ) apache2-mod_security2-debuginfo-2.8.0-3.4.1.x86_64.rpmLinux
SUSE-SU-2015:1851-1(SUSE Linux Enterprise Server 12 ) apache2-mod_security2-debugsource-2.8.0-3.4.1.x86_64.rpmLinux
SUSE-SU-2015:1851-1(SUSE Linux Enterprise Server 12 ) apache2-prefork-2.4.10-14.10.1.x86_64.rpmLinux
SUSE-SU-2015:1851-1(SUSE Linux Enterprise Server 12 ) apache2-prefork-debuginfo-2.4.10-14.10.1.x86_64.rpmLinux
SUSE-SU-2015:1851-1(SUSE Linux Enterprise Server 12 ) apache2-utils-2.4.10-14.10.1.x86_64.rpmLinux
SUSE-SU-2015:1851-1(SUSE Linux Enterprise Server 12 ) apache2-utils-debuginfo-2.4.10-14.10.1.x86_64.rpmLinux
SUSE-SU-2015:1851-1(SUSE Linux Enterprise Server 12 ) apache2-worker-2.4.10-14.10.1.x86_64.rpmLinux
SUSE-SU-2015:1851-1(SUSE Linux Enterprise Server 12 ) apache2-worker-debuginfo-2.4.10-14.10.1.x86_64.rpmLinux
SUSE-SU-2018:3970-1(SUSE Linux Enterprise Server 11-SP4 ) apache2-mod_jk-1.2.40-0.2.5.1.i586.rpmLinux
SUSE-SU-2018:3970-1(SUSE Linux Enterprise Server 11-SP4 ) apache2-mod_jk-1.2.40-0.2.5.1.x86_64.rpmLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234