Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

Search CVE reports


Toggle filters

1 – 6 of 6 results


CVE-2023-41081

Medium priority

Some fixes available 5 of 6

Important: Authentication Bypass CVE-2023-41081 The mod_jk component of Apache Tomcat Connectors in some circumstances, such as when a configuration included "JkOptions +ForwardDirectories" but the configuration did not provide...

1 affected packages

libapache-mod-jk

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
libapache-mod-jk Not affected Fixed Fixed Fixed Fixed
Show less packages

CVE-2018-11759

Medium priority
Not affected

The Apache Web Server (httpd) specific code that normalised the requested path before matching it to the URI-worker map in Apache Tomcat JK (mod_jk) Connector 1.2.0 to 1.2.44 did not handle some edge cases correctly. If only a...

1 affected packages

libapache-mod-jk

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
libapache-mod-jk Not affected Not affected Not affected
Show less packages

CVE-2016-6808

Medium priority
Not affected

Buffer overflow in Apache Tomcat Connectors (mod_jk) before 1.2.42.

1 affected packages

libapache-mod-jk

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
libapache-mod-jk Not affected
Show less packages

CVE-2014-8111

Medium priority

Some fixes available 1 of 4

Apache Tomcat Connectors (mod_jk) before 1.2.41 ignores JkUnmount rules for subtrees of previous JkMount rules, which allows remote attackers to access otherwise restricted artifacts via unspecified vectors.

1 affected packages

libapache-mod-jk

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
libapache-mod-jk Not affected Not affected
Show less packages

CVE-2008-5519

Low priority

Some fixes available 2 of 4

The JK Connector (aka mod_jk) 1.2.0 through 1.2.26 in Apache Tomcat allows remote attackers to obtain sensitive information via an arbitrary request from an HTTP client, in opportunistic circumstances involving (1) a request from...

1 affected packages

libapache-mod-jk

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
libapache-mod-jk
Show less packages

CVE-2007-1860

Unknown priority

Some fixes available 4 of 6

mod_jk in Apache Tomcat JK Web Server Connector 1.2.x before 1.2.23 decodes request URLs within the Apache HTTP Server before passing the URL to Tomcat, which allows remote attackers to access protected pages via a crafted prefix...

1 affected packages

libapache-mod-jk

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
libapache-mod-jk
Show less packages