CVE-2012-1154
published 2012-10-22CVE-2012-1154: mod_cluster 1.0.10 before 1.0.10 CP03 and 1.1.x before 1.1.4, as used in JBoss Enterprise Application Platform 5.1.2, when "ROOT" is set to excludedContexts…
PriorityP430medium4.3CVSS 2.0
AVNACMAuNCPINAN
EPSS
2.59%
83.6th percentile
mod_cluster 1.0.10 before 1.0.10 CP03 and 1.1.x before 1.1.4, as used in JBoss Enterprise Application Platform 5.1.2, when "ROOT" is set to excludedContexts, exposes the root context of the server, which allows remote attackers to bypass access restrictions and gain access to applications deployed on the root context via unspecified vectors.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | mod_cluster | — | — |
| redhat | mod_cluster | — | — |
| redhat | mod_cluster | — | — |
| redhat | mod_cluster | — | — |
| redhat | mod_cluster | — | — |
| redhat | mod_cluster | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Improper Access Control in JBoss mod_cluster
osv·2022-05-17
CVE-2012-1154 [MEDIUM] Improper Access Control in JBoss mod_cluster
Improper Access Control in JBoss mod_cluster
mod_cluster 1.0.10 before 1.0.10 CP03 and 1.1.x before 1.1.4, as used in JBoss Enterprise Application Platform 5.1.2, when "ROOT" is set to excludedContexts, exposes the root context of the server, which allows remote attackers to bypass access restrictions and gain access to applications deployed on the root context via unspecified vectors.
GHSA
Improper Access Control in JBoss mod_cluster
ghsa·2022-05-17
CVE-2012-1154 [MEDIUM] CWE-284 Improper Access Control in JBoss mod_cluster
Improper Access Control in JBoss mod_cluster
mod_cluster 1.0.10 before 1.0.10 CP03 and 1.1.x before 1.1.4, as used in JBoss Enterprise Application Platform 5.1.2, when "ROOT" is set to excludedContexts, exposes the root context of the server, which allows remote attackers to bypass access restrictions and gain access to applications deployed on the root context via unspecified vectors.
Red Hat
mod_cluster registers and exposes the root context of a server by default, despite ROOT being in the excluded-contexts list
vendor_redhat·2011-08-31·CVSS 4.3
CVE-2012-1154 [MEDIUM] mod_cluster registers and exposes the root context of a server by default, despite ROOT being in the excluded-contexts list
mod_cluster registers and exposes the root context of a server by default, despite ROOT being in the excluded-contexts list
mod_cluster 1.0.10 before 1.0.10 CP03 and 1.1.x before 1.1.4, as used in JBoss Enterprise Application Platform 5.1.2, when "ROOT" is set to excludedContexts, exposes the root context of the server, which allows remote attackers to bypass access restrictions and gain access to applications deployed on the root context via unspecified vectors.
No detection rules found.
No public exploits indexed.
http://rhn.redhat.com/errata/RHSA-2012-1010.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1011.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1012.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1052.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1053.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1166.htmlhttp://secunia.com/advisories/49636https://bugzilla.redhat.com/show_bug.cgi?id=802200https://community.jboss.org/message/624018https://issues.jboss.org/browse/MODCLUSTER-253http://rhn.redhat.com/errata/RHSA-2012-1010.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1011.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1012.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1052.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1053.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1166.htmlhttp://secunia.com/advisories/49636https://bugzilla.redhat.com/show_bug.cgi?id=802200https://community.jboss.org/message/624018https://issues.jboss.org/browse/MODCLUSTER-253
2012-10-22
Published