Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2012-1094

Опубликовано: 04 фев. 2012
Источник: redhat
CVSS2: 5

Описание

JBoss AS 7 prior to 7.1.1 and mod_cluster do not handle default hostname in the same way, which can cause the excluded-contexts list to be mismatched and the root context to be exposed.

Отчет

Not vulnerable. This issue only affects community JBoss AS 7 prior to 7.1.1. It does not affect components shipped with any Red Hat products.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss BRMS 5securityNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=798841mod_cluster registers and exposes the root context of a JBoss AS 7 server by default, despite ROOT being in the excluded-contexts list

5 Medium

CVSS2

Связанные уязвимости

CVSS3: 7.5
nvd
больше 6 лет назад

JBoss AS 7 prior to 7.1.1 and mod_cluster do not handle default hostname in the same way, which can cause the excluded-contexts list to be mismatched and the root context to be exposed.

CVSS3: 7.5
debian
больше 6 лет назад

JBoss AS 7 prior to 7.1.1 and mod_cluster do not handle default hostna ...

CVSS3: 7.5
github
больше 4 лет назад

JBoss AS may expose root content if excluded-contexts list is mismatched

5 Medium

CVSS2