Information disclosure in mod_jk - CVE-2023-41081
Published: September 13, 2023
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output by the application when a configuration included "JkOptions +ForwardDirectories" but the configuration did not provide explicit mounts for all possible proxied requests. A remote attacker can view status worker and possibly bypass security constraints configured in httpd.
Affected software
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Server Applications Module
openSUSE Leap
Ubuntu
Oracle Solaris
libapache2-mod-jk (Ubuntu package)
jbcs-httpd24-openssl-pkcs11 (Red Hat package)
jbcs-httpd24-openssl-chil (Red Hat package)
libapache-mod-jk (Ubuntu package)
mod_jk (Red Hat package)
apache2-mod_jk-debugsource
apache2-mod_jk
apache2-mod_jk-debuginfo
jbcs-httpd24-mod_proxy_cluster (Red Hat package)
mod_proxy_cluster (Red Hat package)
jbcs-httpd24-apr-util (Red Hat package)
jbcs-httpd24-mod_http2 (Red Hat package)
jbcs-httpd24-mod_md (Red Hat package)
jbcs-httpd24-httpd (Red Hat package)
jbcs-httpd24-mod_security (Red Hat package)
jbcs-httpd24-curl (Red Hat package)
JBoss Core Services
How to mitigate CVE-2023-41081
libapache2-mod-jk (Ubuntu package) - addressed in versions Ubuntu Pro, 1:1.2.46-1ubuntu0.1, 1:1.2.48-1ubuntu0.1, 1:1.2.48-2ubuntu0.1
jbcs-httpd24-openssl-pkcs11 (Red Hat package) - addressed in versions 0.4.10-34.el7jbcs, 0.4.10-34.el8jbcs
jbcs-httpd24-openssl-chil (Red Hat package) - addressed in versions 1.0.0-19.el7jbcs, 1.0.0-19.el8jbcs
libapache-mod-jk (Ubuntu package) - update to 1:1.2.41-1ubuntu0.1~esm2
mod_jk (Red Hat package) - update to 1.2.49-1.el9_4
apache2-mod_jk-debugsource - addressed in versions 1.2.49-7.9.1, 1.2.50-150100.6.12.1
apache2-mod_jk - addressed in versions 1.2.49-7.9.1, 1.2.50-150100.6.12.1
apache2-mod_jk-debuginfo - addressed in versions 1.2.49-7.9.1, 1.2.50-150100.6.12.1
jbcs-httpd24-mod_proxy_cluster (Red Hat package) - addressed in versions 1.3.19-7.el7jbcs, 1.3.19-7.el8jbcs
mod_proxy_cluster (Red Hat package) - update to 1.3.20-1.el9_4
jbcs-httpd24-apr-util (Red Hat package) - addressed in versions 1.6.1-103.el7jbcs, 1.6.1-103.el8jbcs
jbcs-httpd24-mod_http2 (Red Hat package) - addressed in versions 1.15.19-32.el7jbcs, 1.15.19-32.el8jbcs
jbcs-httpd24-mod_md (Red Hat package) - addressed in versions 2.4.24-2.el7jbcs, 2.4.24-2.el8jbcs
JBoss Core Services - update to 2.4.57 SP2
jbcs-httpd24-httpd (Red Hat package) - addressed in versions 2.4.57-7.el7jbcs, 2.4.57-7.el8jbcs
jbcs-httpd24-mod_security (Red Hat package) - addressed in versions 2.9.3-32.el7jbcs, 2.9.3-32.el8jbcs
jbcs-httpd24-curl (Red Hat package) - addressed in versions 8.4.0-2.el7jbcs, 8.4.0-2.el8jbcs
Oracle Solaris - update to 11.4 SRU 62
External References
Related Security Bulletins
- Information disclosure in Apache Tomcat mod_jk
- Oracle Solaris update for thrid-party components
- Multiple vulnerabilities in Red Hat JBoss Core Services Apache HTTP Server 2.4
- Multiple vulnerabilities in Red Hat JBoss Core Services for RHEL 7 and 8
- SUSE update for apache2-mod_jk
- Red Hat Enterprise Linux 9 update for mod_jk and mod_proxy_cluster
- Ubuntu update for libapache-mod-jk
- SUSE update for apache2-mod_jk
- Ubuntu update for libapache-mod-jk