Apache Tomcat Connectors (mod_jk) before 1.2.41 ignores JkUnmount rules for subtrees of previous JkMount rules, which allows remote attackers to access otherwise restricted artifacts via unspecified vectors.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade libapache-mod-jk | Jul 30, 2024 | Apr 21, 2015 |
| Freebsd | — | Upgrade ap22-mod_jkUpgrade ap24-mod_jk | Dec 10, 2025 | Aug 17, 2015 |
| Oracle Solaris | — | Upgrade web/server/apache-22/module/apache-jk to version 1.2.41-0.175.2.15.0.4.0 on Solaris 11.2Upgrade web/server/apache-22/module/apache-jk to version 1.2.41-0.175.3.1.0.3.0 on Solaris 11.3Upgrade web/server/apache-24/module/apache-jk to version 1.2.41-0.175.3.1.0.3.0 on Solaris 11.3 | May 29, 2017 | Apr 21, 2015 |
| Red Hat Jboss Eap | — | Upgrade Red Hat JBoss EAP to the latest version | Sep 19, 2024 | Apr 14, 2015 |
| Suse | — | Upgrade apache2-mod_jkUpgrade apache2-develUpgrade apache2Upgrade apache2-example-pagesUpgrade apache2-mod_security2Upgrade apache2-workerUpgrade apache2-preforkUpgrade apache2-mod_auth_kerbUpgrade apache2-docUpgrade apache2-utils | Dec 18, 2015 | Apr 21, 2015 |
| Ubuntu | — | Upgrade libapache-mod-jk | Nov 19, 2024 | Apr 21, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub