Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-46544

Опубликовано: 23 сент. 2024
Источник: debian
EPSS Низкий

Описание

Incorrect Default Permissions vulnerability in Apache Tomcat Connectors allows local users to view and modify shared memory containing mod_jk configuration which may lead to information disclosure and/or denial of service. This issue affects Apache Tomcat Connectors: from 1.2.9-beta through 1.2.49. Only mod_jk on Unix like systems is affected. Neither the ISAPI redirector nor mod_jk on Windows is affected. Users are recommended to upgrade to version 1.2.50, which fixes the issue.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libapache-mod-jkfixed1:1.2.50-1package
libapache-mod-jkfixed1:1.2.48-2+deb12u2bookwormpackage

Примечания

  • https://www.openwall.com/lists/oss-security/2024/09/23/1

  • Fixed by: https://github.com/apache/tomcat-connectors/commit/d55706e92b65018c2e4c7ab14014a996b0174966 (JK_1_2_50)

EPSS

Процентиль: 8%
0.00029
Низкий

Связанные уязвимости

CVSS3: 5.9
ubuntu
больше 1 года назад

Incorrect Default Permissions vulnerability in Apache Tomcat Connectors allows local users to view and modify shared memory containing mod_jk configuration which may lead to information disclosure and/or denial of service. This issue affects Apache Tomcat Connectors: from 1.2.9-beta through 1.2.49. Only mod_jk on Unix like systems is affected. Neither the ISAPI redirector nor mod_jk on Windows is affected. Users are recommended to upgrade to version 1.2.50, which fixes the issue.

CVSS3: 5.9
redhat
больше 1 года назад

Incorrect Default Permissions vulnerability in Apache Tomcat Connectors allows local users to view and modify shared memory containing mod_jk configuration which may lead to information disclosure and/or denial of service. This issue affects Apache Tomcat Connectors: from 1.2.9-beta through 1.2.49. Only mod_jk on Unix like systems is affected. Neither the ISAPI redirector nor mod_jk on Windows is affected. Users are recommended to upgrade to version 1.2.50, which fixes the issue.

CVSS3: 5.9
nvd
больше 1 года назад

Incorrect Default Permissions vulnerability in Apache Tomcat Connectors allows local users to view and modify shared memory containing mod_jk configuration which may lead to information disclosure and/or denial of service. This issue affects Apache Tomcat Connectors: from 1.2.9-beta through 1.2.49. Only mod_jk on Unix like systems is affected. Neither the ISAPI redirector nor mod_jk on Windows is affected. Users are recommended to upgrade to version 1.2.50, which fixes the issue.

suse-cvrf
12 месяцев назад

Security update for apache2-mod_jk

rocky
8 месяцев назад

Moderate: mod_jk bug fix update

EPSS

Процентиль: 8%
0.00029
Низкий