CVE-2014-8111
published 2015-04-21CVE-2014-8111: Apache Tomcat Connectors (mod_jk) before 1.2.41 ignores JkUnmount rules for subtrees of previous JkMount rules, which allows remote attackers to access…
PriorityP336medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
7.11%
93.5th percentile
Apache Tomcat Connectors (mod_jk) before 1.2.41 ignores JkUnmount rules for subtrees of previous JkMount rules, which allows remote attackers to access otherwise restricted artifacts via unspecified vectors.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomcat_connectors | <= 1.2.40 | — |
| debian | libapache-mod-jk | < libapache-mod-jk 1:1.2.40+svn150520-1 (bookworm) | libapache-mod-jk 1:1.2.40+svn150520-1 (bookworm) |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
mod_jk: information leak due to incorrect JkMount/JkUnmount directives processing
vendor_redhat·2015-04-14·CVSS 5.0
CVE-2014-8111 [MEDIUM] mod_jk: information leak due to incorrect JkMount/JkUnmount directives processing
mod_jk: information leak due to incorrect JkMount/JkUnmount directives processing
Apache Tomcat Connectors (mod_jk) before 1.2.41 ignores JkUnmount rules for subtrees of previous JkMount rules, which allows remote attackers to access otherwise restricted artifacts via unspecified vectors.
It was discovered that a JkUnmount rule for a subtree of a previous JkMount rule could be ignored. This could allow a remote attacker to potentially access a private artifact in a tree that would otherwise not be accessible to them.
Statement: Red Hat Product Security has rated this issue as having Moderate security impact. This issue is not currently planned to be addressed in future updates of Red Hat Enterprise Application Platform 4 and 5, and Red Hat JBoss Web Server 1. For additional information,
Debian
CVE-2014-8111: libapache-mod-jk - Apache Tomcat Connectors (mod_jk) before 1.2.41 ignores JkUnmount rules for subt...
vendor_debian·2014·CVSS 5.0
CVE-2014-8111 [MEDIUM] CVE-2014-8111: libapache-mod-jk - Apache Tomcat Connectors (mod_jk) before 1.2.41 ignores JkUnmount rules for subt...
Apache Tomcat Connectors (mod_jk) before 1.2.41 ignores JkUnmount rules for subtrees of previous JkMount rules, which allows remote attackers to access otherwise restricted artifacts via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 1:1.2.40+svn150520-1)
bullseye: resolved (fixed in 1:1.2.40+svn150520-1)
forky: resolved (fixed in 1:1.2.40+svn150520-1)
sid: resolved (fixed in 1:1.2.40+svn150520-1)
trixie: resolved (fixed in 1:1.2.40+svn150520-1)
GHSA
GHSA-f49p-9mwv-783f: Apache Tomcat Connectors (mod_jk) before 1
ghsa_unreviewed·2022-05-14
CVE-2014-8111 [MEDIUM] CWE-200 GHSA-f49p-9mwv-783f: Apache Tomcat Connectors (mod_jk) before 1
Apache Tomcat Connectors (mod_jk) before 1.2.41 ignores JkUnmount rules for subtrees of previous JkMount rules, which allows remote attackers to access otherwise restricted artifacts via unspecified vectors.
OSV
CVE-2014-8111: Apache Tomcat Connectors (mod_jk) before 1
osv·2015-04-21·CVSS 5.0
CVE-2014-8111 [MEDIUM] CVE-2014-8111: Apache Tomcat Connectors (mod_jk) before 1
Apache Tomcat Connectors (mod_jk) before 1.2.41 ignores JkUnmount rules for subtrees of previous JkMount rules, which allows remote attackers to access otherwise restricted artifacts via unspecified vectors.
No detection rules found.
No public exploits indexed.
http://rhn.redhat.com/errata/RHSA-2015-0846.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0847.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0848.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0849.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1641.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1642.htmlhttp://www.debian.org/security/2015/dsa-3278http://www.securityfocus.com/bid/74265https://lists.apache.org/thread.html/277d42b48b6e9aef50949c0dcc79ce21693091d73da246b3c1981925%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/5b7a23e245c93235c503900da854a143596d901bf1a1f67e851a5de4%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/8d2a579bbd977c225c70cb23b0ec54865fb0dab5da3eff1e060c9935%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/ba661b0edd913b39ff129a32d855620dd861883ade05fd88a8ce517d%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r5c616dfc49156e4b06ffab842800c80f4425924d0f20c452c127a53c%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/rf8e8c091182b45daa50d3557cad9b10bb4198e3f08cf8f1c66a1b08d%40%3Cdev.tomcat.apache.org%3Ehttp://rhn.redhat.com/errata/RHSA-2015-0846.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0847.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0848.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0849.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1641.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1642.htmlhttp://www.debian.org/security/2015/dsa-3278http://www.securityfocus.com/bid/74265https://lists.apache.org/thread.html/277d42b48b6e9aef50949c0dcc79ce21693091d73da246b3c1981925%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/5b7a23e245c93235c503900da854a143596d901bf1a1f67e851a5de4%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/8d2a579bbd977c225c70cb23b0ec54865fb0dab5da3eff1e060c9935%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/ba661b0edd913b39ff129a32d855620dd861883ade05fd88a8ce517d%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r5c616dfc49156e4b06ffab842800c80f4425924d0f20c452c127a53c%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/rf8e8c091182b45daa50d3557cad9b10bb4198e3f08cf8f1c66a1b08d%40%3Cdev.tomcat.apache.org%3E
2015-04-21
Published