cbcvebase.
CVE-2018-11759
published 2018-10-31

CVE-2018-11759: The Apache Web Server (httpd) specific code that normalised the requested path before matching it to the URI-worker map in Apache Tomcat JK (mod_jk) Connector…

PriorityP185high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
90.65%
99.8th percentile
The Apache Web Server (httpd) specific code that normalised the requested path before matching it to the URI-worker map in Apache Tomcat JK (mod_jk) Connector 1.2.0 to 1.2.44 did not handle some edge cases correctly. If only a sub-set of the URLs supported by Tomcat were exposed via httpd, then it was possible for a specially constructed request to expose application functionality through the reverse proxy that was not intended for clients accessing the application via the reverse proxy. It was also possible in some configurations for a specially constructed request to bypass the access controls configured in httpd. While there is some overlap between this issue and CVE-2018-1323, they are not identical.

Affected

5 ranges
VendorProductVersion rangeFixed in
apachetomcat_jk_connector1.2.0 – 1.2.44
apache_software_foundationapache_tomcat_connectors
debiandebian_linux
debiandebian_linux
debianlibapache-mod-jk< libapache-mod-jk 1:1.2.46-1 (bookworm)libapache-mod-jk 1:1.2.46-1 (bookworm)

Detection & IOCsextracted from sources · hover to see the quote

url/jkstatus
url/jkstatus;
otherJK Status Manager
  • ·The bypass only applies when httpd (Apache Web Server) is used as a reverse proxy in front of Tomcat via mod_jk, and only when a sub-set of Tomcat URLs are exposed through httpd — direct Tomcat access is not affected.
  • ·Access control bypass is configuration-dependent — only some httpd configurations are vulnerable to the ACL bypass variant of this issue.
  • ·Red Hat JBoss Web Server 3 is listed as Not Affected; Red Hat JBoss Enterprise Application Platform 5 and JBoss Enterprise Web Server 2 are listed as Will Not Fix — scope detection should account for these variants.

CVSS provenance

nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv7.5HIGH
vulncheck7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.