CVE-2018-11759
published 2018-10-31CVE-2018-11759: The Apache Web Server (httpd) specific code that normalised the requested path before matching it to the URI-worker map in Apache Tomcat JK (mod_jk) Connector…
PriorityP185high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
90.65%
99.8th percentile
The Apache Web Server (httpd) specific code that normalised the requested path before matching it to the URI-worker map in Apache Tomcat JK (mod_jk) Connector 1.2.0 to 1.2.44 did not handle some edge cases correctly. If only a sub-set of the URLs supported by Tomcat were exposed via httpd, then it was possible for a specially constructed request to expose application functionality through the reverse proxy that was not intended for clients accessing the application via the reverse proxy. It was also possible in some configurations for a specially constructed request to bypass the access controls configured in httpd. While there is some overlap between this issue and CVE-2018-1323, they are not identical.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomcat_jk_connector | 1.2.0 – 1.2.44 | — |
| apache_software_foundation | apache_tomcat_connectors | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | libapache-mod-jk | < libapache-mod-jk 1:1.2.46-1 (bookworm) | libapache-mod-jk 1:1.2.46-1 (bookworm) |
Detection & IOCsextracted from sources · hover to see the quote
url/jkstatus
url/jkstatus;
otherJK Status Manager
- ·The bypass only applies when httpd (Apache Web Server) is used as a reverse proxy in front of Tomcat via mod_jk, and only when a sub-set of Tomcat URLs are exposed through httpd — direct Tomcat access is not affected. ↗
- ·Access control bypass is configuration-dependent — only some httpd configurations are vulnerable to the ACL bypass variant of this issue. ↗
- ·Red Hat JBoss Web Server 3 is listed as Not Affected; Red Hat JBoss Enterprise Application Platform 5 and JBoss Enterprise Web Server 2 are listed as Will Not Fix — scope detection should account for these variants. ↗
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv7.5HIGH
vulncheck7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
mod_jk: connector path traversal due to mishandled HTTP requests in httpd
vendor_redhat·2018-10-31·CVSS 7.5
CVE-2018-11759 [HIGH] CWE-22 mod_jk: connector path traversal due to mishandled HTTP requests in httpd
mod_jk: connector path traversal due to mishandled HTTP requests in httpd
The Apache Web Server (httpd) specific code that normalised the requested path before matching it to the URI-worker map in Apache Tomcat JK (mod_jk) Connector 1.2.0 to 1.2.44 did not handle some edge cases correctly. If only a sub-set of the URLs supported by Tomcat were exposed via httpd, then it was possible for a specially constructed request to expose application functionality through the reverse proxy that was not intended for clients accessing the application via the reverse proxy. It was also possible in some configurations for a specially constructed request to bypass the access controls configured in httpd. While there is some overlap between this issue and CVE-2018-1323, they are not identical.
Package: m
Debian
CVE-2018-11759: libapache-mod-jk - The Apache Web Server (httpd) specific code that normalised the requested path b...
vendor_debian·2018·CVSS 7.5
CVE-2018-11759 [HIGH] CVE-2018-11759: libapache-mod-jk - The Apache Web Server (httpd) specific code that normalised the requested path b...
The Apache Web Server (httpd) specific code that normalised the requested path before matching it to the URI-worker map in Apache Tomcat JK (mod_jk) Connector 1.2.0 to 1.2.44 did not handle some edge cases correctly. If only a sub-set of the URLs supported by Tomcat were exposed via httpd, then it was possible for a specially constructed request to expose application functionality through the reverse proxy that was not intended for clients accessing the application via the reverse proxy. It was also possible in some configurations for a specially constructed request to bypass the access controls configured in httpd. While there is some overlap between this issue and CVE-2018-1323, they are not identical.
Scope: local
bookworm: resolved (fixed in 1:1.2.46-1)
bullseye: resolved (fixed in 1:1
GHSA
GHSA-5q2c-33mg-8m75: The Apache Web Server (httpd) specific code that normalised the requested path before matching it to the URI-worker map in Apache Tomcat JK (mod_jk) C
ghsa_unreviewed·2022-05-14·CVSS 7.5
CVE-2018-11759 [HIGH] CWE-22 GHSA-5q2c-33mg-8m75: The Apache Web Server (httpd) specific code that normalised the requested path before matching it to the URI-worker map in Apache Tomcat JK (mod_jk) C
The Apache Web Server (httpd) specific code that normalised the requested path before matching it to the URI-worker map in Apache Tomcat JK (mod_jk) Connector 1.2.0 to 1.2.44 did not handle some edge cases correctly. If only a sub-set of the URLs supported by Tomcat were exposed via httpd, then it was possible for a specially constructed request to expose application functionality through the reverse proxy that was not intended for clients accessing the application via the reverse proxy. It was also possible in some configurations for a specially constructed request to bypass the access controls configured in httpd. While there is some overlap between this issue and CVE-2018-1323, they are not identical.
OSV
CVE-2018-11759: The Apache Web Server (httpd) specific code that normalised the requested path before matching it to the URI-worker map in Apache Tomcat JK (mod_jk) C
osv·2018-10-31·CVSS 7.5
CVE-2018-11759 [HIGH] CVE-2018-11759: The Apache Web Server (httpd) specific code that normalised the requested path before matching it to the URI-worker map in Apache Tomcat JK (mod_jk) C
The Apache Web Server (httpd) specific code that normalised the requested path before matching it to the URI-worker map in Apache Tomcat JK (mod_jk) Connector 1.2.0 to 1.2.44 did not handle some edge cases correctly. If only a sub-set of the URLs supported by Tomcat were exposed via httpd, then it was possible for a specially constructed request to expose application functionality through the reverse proxy that was not intended for clients accessing the application via the reverse proxy. It was also possible in some configurations for a specially constructed request to bypass the access controls configured in httpd. While there is some overlap between this issue and CVE-2018-1323, they are not identical.
VulnCheck
Apache Tomcat Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
vulncheck·2018·CVSS 7.5
CVE-2018-11759 [HIGH] Apache Tomcat Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Apache Tomcat Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The Apache Web Server (httpd) specific code that normalised the requested path before matching it to the URI-worker map in Apache Tomcat JK (mod_jk) Connector 1.2.0 to 1.2.44 did not handle some edge cases correctly. If only a sub-set of the URLs supported by Tomcat were exposed via httpd, then it was possible for a specially constructed request to expose application functionality through the reverse proxy that was not intended for clients accessing the application via the reverse proxy. It was also possible in some configurations for a specially constructed request to bypass the access controls configured in httpd. While there is some overlap between this issue and CVE-2018-1323, they are not ide
No detection rules found.
Nuclei
Apache Tomcat JK Connect <=1.2.44 - Manager Access
nuclei·CVSS 7.5
CVE-2018-11759 [HIGH] Apache Tomcat JK Connect <=1.2.44 - Manager Access
Apache Tomcat JK Connect <=1.2.44 - Manager Access
Apache Tomcat JK (mod_jk) Connector 1.2.0 to 1.2.44 allows specially constructed requests to expose application functionality through the reverse proxy. It is also possible in some configurations for a specially constructed request to bypass the access controls configured in httpd. While there is some overlap between this issue and CVE-2018-1323, they are not identical.
Template:
id: CVE-2018-11759
info:
name: Apache Tomcat JK Connect <=1.2.44 - Manager Access
author: harshbothra_
severity: high
description: |
Apache Tomcat JK (mod_jk) Connector 1.2.0 to 1.2.44 allows specially constructed requests to expose application functionality through the reverse proxy. It is also possible in some configurations for a specially constructed reque
CTF
Java Box / README
ctf_writeups·2024
Java Box / README
# Java Box
> I used to hate black box web challenges in CTFs, but then I remembered, my day job as a pentester also requires black box testing. Sometimes, what seems like a black box isn’t so black after all.
## About the Challenge
This challenge includes a website without source code, featuring only one functionality: `/register`.
After registering with any username and password, you’re redirected to the `/dashboard` page.
There’s an interesting jwt cookie here with an `isAdmin` flag set to false.
This means to get the flag, we’ll need to set `isAdmin` flag to true.
## How to Solve?
We initially tried a few common techniques:
- Bruteforcing the key with the Rockyou wordlist
- Changing the algorithm to none
- Signing the token with an empty key
- Etc
But none of these methods wo
Bugzilla
CVE-2018-11759 mod_jk: connector path traversal due to mishandled HTTP requests in httpd
bugzilla·2018-11-02·CVSS 7.5
CVE-2018-11759 [HIGH] CVE-2018-11759 mod_jk: connector path traversal due to mishandled HTTP requests in httpd
CVE-2018-11759 mod_jk: connector path traversal due to mishandled HTTP requests in httpd
A flaw was found in Apache Tomcat JK mod_jk Connector 1.2.0 to 1.2.44. The Apache Web Server (httpd) specific code that normalised the requested path before matching it to the URI-worker map in Apache Tomcat JK (mod_jk) Connector did not handle some edge cases correctly. If only a sub-set of the URLs supported by Tomcat were exposed via httpd, then it was possible for a specially constructed request to expose application functionality through the reverse proxy that was not intended for clients accessing the application via the reverse proxy. It was also possible in some configurations for a specially constructed request to bypass the access controls configured in httpd. While there is some overlap bet
http://www.securityfocus.com/bid/105888https://access.redhat.com/errata/RHSA-2019:0366https://access.redhat.com/errata/RHSA-2019:0367https://lists.apache.org/thread.html/277d42b48b6e9aef50949c0dcc79ce21693091d73da246b3c1981925%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/5b7a23e245c93235c503900da854a143596d901bf1a1f67e851a5de4%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/6d564bb0ab73d6b3efdd1d6b1c075d1a2c84ecd84a4159d6122529ad%40%3Cannounce.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/8d2a579bbd977c225c70cb23b0ec54865fb0dab5da3eff1e060c9935%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/ba661b0edd913b39ff129a32d855620dd861883ade05fd88a8ce517d%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r5c616dfc49156e4b06ffab842800c80f4425924d0f20c452c127a53c%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/rf8e8c091182b45daa50d3557cad9b10bb4198e3f08cf8f1c66a1b08d%40%3Cdev.tomcat.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2018/12/msg00007.htmlhttps://www.debian.org/security/2018/dsa-4357https://www.oracle.com/security-alerts/cpujan2020.htmlhttp://www.securityfocus.com/bid/105888https://access.redhat.com/errata/RHSA-2019:0366https://access.redhat.com/errata/RHSA-2019:0367https://lists.apache.org/thread.html/277d42b48b6e9aef50949c0dcc79ce21693091d73da246b3c1981925%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/5b7a23e245c93235c503900da854a143596d901bf1a1f67e851a5de4%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/6d564bb0ab73d6b3efdd1d6b1c075d1a2c84ecd84a4159d6122529ad%40%3Cannounce.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/8d2a579bbd977c225c70cb23b0ec54865fb0dab5da3eff1e060c9935%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/ba661b0edd913b39ff129a32d855620dd861883ade05fd88a8ce517d%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r5c616dfc49156e4b06ffab842800c80f4425924d0f20c452c127a53c%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/rf8e8c091182b45daa50d3557cad9b10bb4198e3f08cf8f1c66a1b08d%40%3Cdev.tomcat.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2018/12/msg00007.htmlhttps://www.debian.org/security/2018/dsa-4357https://www.oracle.com/security-alerts/cpujan2020.html
2018-10-31
Published
Exploited in the wild