CVE-2011-4608
published 2012-01-27CVE-2011-4608: mod_cluster in JBoss Enterprise Application Platform 5.1.2 for Red Hat Linux allows worker nodes to register with arbitrary virtual hosts, which allows remote…
PriorityP345high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
3.20%
86.7th percentile
mod_cluster in JBoss Enterprise Application Platform 5.1.2 for Red Hat Linux allows worker nodes to register with arbitrary virtual hosts, which allows remote attackers to bypass intended access restrictions and provide malicious content, hijack sessions, and steal credentials by registering from an external vhost that does not enforce security constraints.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | jboss_enterprise_application_platform | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
mod_cluster: malicious worker nodes can register on any vhost
vendor_redhat·2012-01-18·CVSS 7.5
CVE-2011-4608 [HIGH] CWE-863 mod_cluster: malicious worker nodes can register on any vhost
mod_cluster: malicious worker nodes can register on any vhost
mod_cluster in JBoss Enterprise Application Platform 5.1.2 for Red Hat Linux allows worker nodes to register with arbitrary virtual hosts, which allows remote attackers to bypass intended access restrictions and provide malicious content, hijack sessions, and steal credentials by registering from an external vhost that does not enforce security constraints.
GHSA
GHSA-3vmm-p7jr-jw44: mod_cluster in JBoss Enterprise Application Platform 5
ghsa_unreviewed·2022-05-17
CVE-2011-4608 [HIGH] GHSA-3vmm-p7jr-jw44: mod_cluster in JBoss Enterprise Application Platform 5
mod_cluster in JBoss Enterprise Application Platform 5.1.2 for Red Hat Linux allows worker nodes to register with arbitrary virtual hosts, which allows remote attackers to bypass intended access restrictions and provide malicious content, hijack sessions, and steal credentials by registering from an external vhost that does not enforce security constraints.
No detection rules found.
No public exploits indexed.
http://www.redhat.com/support/errata/RHSA-2012-0035.htmlhttp://www.redhat.com/support/errata/RHSA-2012-0036.htmlhttp://www.redhat.com/support/errata/RHSA-2012-0037.htmlhttp://www.redhat.com/support/errata/RHSA-2012-0038.htmlhttp://www.redhat.com/support/errata/RHSA-2012-0039.htmlhttp://www.redhat.com/support/errata/RHSA-2012-0040.htmlhttp://www.securityfocus.com/bid/51554http://www.securitytracker.com/id?1026545https://bugzilla.redhat.com/show_bug.cgi?id=767020https://exchange.xforce.ibmcloud.com/vulnerabilities/72460http://www.redhat.com/support/errata/RHSA-2012-0035.htmlhttp://www.redhat.com/support/errata/RHSA-2012-0036.htmlhttp://www.redhat.com/support/errata/RHSA-2012-0037.htmlhttp://www.redhat.com/support/errata/RHSA-2012-0038.htmlhttp://www.redhat.com/support/errata/RHSA-2012-0039.htmlhttp://www.redhat.com/support/errata/RHSA-2012-0040.htmlhttp://www.securityfocus.com/bid/51554http://www.securitytracker.com/id?1026545https://bugzilla.redhat.com/show_bug.cgi?id=767020https://exchange.xforce.ibmcloud.com/vulnerabilities/72460
2012-01-27
Published