what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

Ubuntu Security Notice USN-6826-1

Ubuntu Security Notice USN-6826-1
Posted Jun 12, 2024
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 6826-1 - Karl von Randow discovered that mod_jk was vulnerable to an authentication bypass. If the configuration did not provide explicit mounts for all possible proxied requests, an attacker could possibly use this vulnerability to bypass security constraints configured in httpd.

tags | advisory
systems | linux, ubuntu
advisories | CVE-2023-41081
SHA-256 | cf6017d31a48fcb0d18e99eff25ef34b45a6980db67fe71108a69071cda964a1

Ubuntu Security Notice USN-6826-1

Change Mirror Download
==========================================================================
Ubuntu Security Notice USN-6826-1
June 11, 2024

libapache-mod-jk vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 23.10
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS

Summary:

mod_jk could allow unintended access to network services.

Software Description:
- libapache-mod-jk: Apache 2 connector for the Tomcat Java servlet engine

Details:

Karl von Randow discovered that mod_jk was vulnerable to an authentication
bypass. If the configuration did not provide explicit mounts for all
possible proxied requests, an attacker could possibly use this
vulnerability to bypass security constraints configured in httpd.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 23.10
libapache2-mod-jk 1:1.2.48-2ubuntu0.1

Ubuntu 22.04 LTS
libapache2-mod-jk 1:1.2.48-1ubuntu0.1

Ubuntu 20.04 LTS
libapache2-mod-jk 1:1.2.46-1ubuntu0.1

Ubuntu 18.04 LTS
libapache2-mod-jk 1:1.2.43-1ubuntu0.1~esm1
Available with Ubuntu Pro

Ubuntu 16.04 LTS
libapache2-mod-jk 1:1.2.41-1ubuntu0.1~esm1
Available with Ubuntu Pro

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-6826-1
CVE-2023-41081

Package Information:
https://launchpad.net/ubuntu/+source/libapache-mod-jk/1:1.2.48-2ubuntu0.1
https://launchpad.net/ubuntu/+source/libapache-mod-jk/1:1.2.48-1ubuntu0.1
https://launchpad.net/ubuntu/+source/libapache-mod-jk/1:1.2.46-1ubuntu0.1
Login or Register to add favorites

File Archive:

July 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Jul 1st
    27 Files
  • 2
    Jul 2nd
    10 Files
  • 3
    Jul 3rd
    35 Files
  • 4
    Jul 4th
    0 Files
  • 5
    Jul 5th
    0 Files
  • 6
    Jul 6th
    0 Files
  • 7
    Jul 7th
    0 Files
  • 8
    Jul 8th
    0 Files
  • 9
    Jul 9th
    0 Files
  • 10
    Jul 10th
    0 Files
  • 11
    Jul 11th
    0 Files
  • 12
    Jul 12th
    0 Files
  • 13
    Jul 13th
    0 Files
  • 14
    Jul 14th
    0 Files
  • 15
    Jul 15th
    0 Files
  • 16
    Jul 16th
    0 Files
  • 17
    Jul 17th
    0 Files
  • 18
    Jul 18th
    0 Files
  • 19
    Jul 19th
    0 Files
  • 20
    Jul 20th
    0 Files
  • 21
    Jul 21st
    0 Files
  • 22
    Jul 22nd
    0 Files
  • 23
    Jul 23rd
    0 Files
  • 24
    Jul 24th
    0 Files
  • 25
    Jul 25th
    0 Files
  • 26
    Jul 26th
    0 Files
  • 27
    Jul 27th
    0 Files
  • 28
    Jul 28th
    0 Files
  • 29
    Jul 29th
    0 Files
  • 30
    Jul 30th
    0 Files
  • 31
    Jul 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close