CVE-2023-41081
CVSS 3.1 Score 7.5 of 10 (high)
Details
Summary
CVE-2023-41081: Crucial Authentication Bypass Vulnerability in mod_jk The mod_jk component of Apache Tomcat Connectors, specifically versions 1.2.0 through 1.2.48, contains an authentication bypass issue (CVE-2023-41081). In certain configurations where "JkOptions +ForwardDirectories" is included but explicit mounts are not provided for all possible proxied requests, mod_jk employs an implicit mapping and directs the request to the first defined worker. This implicit mapping may result in unintended exposure of the status worker and security constraint bypass in httpd. To mitigate this vulnerability, users should upgrade to version 1.2.49, which addresses the issue. It is important to note that only mod_jk is affected, and the ISAPI redirector remains unaffected.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Apache Software Foundation