CVE-2014-8111

NameCVE-2014-8111
DescriptionApache Tomcat Connectors (mod_jk) before 1.2.41 ignores JkUnmount rules for subtrees of previous JkMount rules, which allows remote attackers to access otherwise restricted artifacts via unspecified vectors.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, GitHub code/issues, web search, more)
ReferencesDLA-240-1, DSA-3278-1
NVD severitymedium (attack range: remote)
Debian Bugs783233

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
libapache-mod-jk (PTS)wheezy, wheezy (security)1:1.2.37-1+deb7u1fixed
jessie (security), jessie1:1.2.37-4+deb8u1fixed
buster, sid, stretch1:1.2.42-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
libapache-mod-jksource(unstable)1:1.2.40+svn150520-1medium783233
libapache-mod-jksourcejessie1:1.2.37-4+deb8u1mediumDSA-3278-1
libapache-mod-jksourcesqueeze1:1.2.30-1squeeze2mediumDLA-240-1
libapache-mod-jksourcewheezy1:1.2.37-1+deb7u1mediumDSA-3278-1

Notes

Fix: http://svn.apache.org/r1647017

Search for package or bug name: Reporting problems