CVE-2023-41081

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Sep 13, 2023
Updated: Sep 29, 2023

Summary

CVE-2023-41081: Crucial Authentication Bypass Vulnerability in mod_jk The mod_jk component of Apache Tomcat Connectors, specifically versions 1.2.0 through 1.2.48, contains an authentication bypass issue (CVE-2023-41081). In certain configurations where "JkOptions +ForwardDirectories" is included but explicit mounts are not provided for all possible proxied requests, mod_jk employs an implicit mapping and directs the request to the first defined worker. This implicit mapping may result in unintended exposure of the status worker and security constraint bypass in httpd. To mitigate this vulnerability, users should upgrade to version 1.2.49, which addresses the issue. It is important to note that only mod_jk is affected, and the ISAPI redirector remains unaffected.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Prioritize, Pinpoint, and Act to Prevent Vulnerability Exploits with Recorded Future

Note: This is just a basic overview providing quick insights into CVE-2023-41081 information. Gain full access to comprehensive CVE data, third party vulnerabilities, compromised credentials and more with Recorded Future
  • Gain complete coverage of your cyber, third party, and physical attack surface
  • Proactively mitigate threats before they turn into costly attacks
  • Make fast, effective, data-driven decisions