SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-11759

If only a sub-set of the URLs supported by Tomcat were exposed via httpd, then it was possible for a specially constructed request to expose application functionality through the reverse proxy that was not intended for clients accessing the application…

HIGH 7.5EPSS 90.6%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 90.6%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.

Description

The Apache Web Server (httpd) specific code that normalised the requested path before matching it to the URI-worker map in Apache Tomcat JK (mod_jk) Connector 1.2.0 to 1.2.44 did not handle some edge cases correctly. If only a sub-set of the URLs supported by Tomcat were exposed via httpd, then it was possible for a specially constructed request to expose application functionality through the reverse proxy that was not intended for clients accessing the application via the reverse proxy. It was also possible in some configurations for a specially constructed request to bypass the access controls configured in httpd. While there is some overlap between this issue and CVE-2018-1323, they are not identical.

CVSS 3.0
7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
90.65% probability · 100th percentile
CISA KEV
Not listed
Weakness
CWE-22
Affected
apache/tomcat jk connector · debian/debian linux · redhat/jboss core services
Source
security@apache.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.