5
CVSSv2

CVE-2014-8111

Published: 21/04/2015 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Apache Tomcat Connectors (mod_jk) prior to 1.2.41 ignores JkUnmount rules for subtrees of previous JkMount rules, which allows remote malicious users to access otherwise restricted artifacts via unspecified vectors.

Vulnerable Product Search on Vulmon Subscribe to Product

apache tomcat connectors

Vendor Advisories

Debian Bug report logs - #783233 CVE-2014-8111: mod_jk ignores JkUnmount rules for subtrees of previous JkMount rules Package: src:libapache-mod-jk; Maintainer for src:libapache-mod-jk is Debian Java Maintainers <pkg-java-maintainers@listsaliothdebianorg>; Reported by: Raphael Hertzog <hertzog@debianorg> Date: Fri ...
An information disclosure flaw due to incorrect JkMount/JkUnmount directives processing was found in the Apache 2 module mod_jk to forward requests from the Apache web server to Tomcat A JkUnmount rule for a subtree of a previous JkMount rule could be ignored This could allow a remote attacker to potentially access a private artifact in a tree th ...
It was discovered that a JkUnmount rule for a subtree of a previous JkMount rule could be ignored This could allow a remote attacker to potentially access a private artifact in a tree that would otherwise not be accessible to them ...