Improper Access Control in JBoss mod_cluster
Moderate severity
GitHub Reviewed
Published
May 17, 2022
to the GitHub Advisory Database
•
Updated Jan 30, 2023
Package
Affected versions
>= 1.1.0, < 1.1.4
Patched versions
1.1.4
Description
Published by the National Vulnerability Database
Oct 22, 2012
Published to the GitHub Advisory Database
May 17, 2022
Reviewed
Nov 1, 2022
Last updated
Jan 30, 2023
mod_cluster 1.0.10 before 1.0.10 CP03 and 1.1.x before 1.1.4, as used in JBoss Enterprise Application Platform 5.1.2, when "ROOT" is set to excludedContexts, exposes the root context of the server, which allows remote attackers to bypass access restrictions and gain access to applications deployed on the root context via unspecified vectors.
References