Description
mod_cluster 1.0.10 before 1.0.10 CP03 and 1.1.x before 1.1.4, as used in JBoss Enterprise Application Platform 5.1.2, when "ROOT" is set to excludedContexts, exposes the root context of the server, which allows remote attackers to bypass access restrictions and gain access to applications deployed on the root context via unspecified vectors.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-5262 | mod_cluster 1.0.10 before 1.0.10 CP03 and 1.1.x before 1.1.4, as used in JBoss Enterprise Application Platform 5.1.2, when "ROOT" is set to excludedContexts, exposes the root context of the server, which allows remote attackers to bypass access restrictions and gain access to applications deployed on the root context via unspecified vectors. |
Github GHSA |
GHSA-v2fp-h4qx-x3r6 | Improper Access Control in JBoss mod_cluster |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T18:45:27.439Z
Reserved: 2012-02-14T00:00:00.000Z
Link: CVE-2012-1154
No data.
Status : Modified
Published: 2012-10-22T23:55:05.417
Modified: 2026-04-29T01:13:23.040
Link: CVE-2012-1154
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA