#VU80760 Information disclosure in mod_jk - CVE-2023-41081
Published: September 13, 2023
mod_jk
Apache Foundation
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output by the application when a configuration included "JkOptions +ForwardDirectories" but the configuration did not provide explicit mounts for all possible proxied requests. A remote attacker can view status worker and possibly bypass security constraints configured in httpd.