CVE-2023-41081

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Sep 13, 2023
Updated: Sep 29, 2023

Summary

CVE-2023-41081: Crucial Authentication Bypass Vulnerability in mod_jk The mod_jk component of Apache Tomcat Connectors, specifically versions 1.2.0 through 1.2.48, contains an authentication bypass issue (CVE-2023-41081). In certain configurations where "JkOptions +ForwardDirectories" is included but explicit mounts are not provided for all possible proxied requests, mod_jk employs an implicit mapping and directs the request to the first defined worker. This implicit mapping may result in unintended exposure of the status worker and security constraint bypass in httpd. To mitigate this vulnerability, users should upgrade to version 1.2.49, which addresses the issue. It is important to note that only mod_jk is affected, and the ISAPI redirector remains unaffected.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share