Back to search
CVE-2012-1154
Published: Oct 22, 2012
Modified: Aug 6, 2024
PUBLISHED
Description
mod_cluster 1.0.10 before 1.0.10 CP03 and 1.1.x before 1.1.4, as used in JBoss Enterprise Application Platform 5.1.2, when "ROOT" is set to excludedContexts, exposes the root context of the server, which allows remote attackers to bypass access restrictions and gain access to applications deployed on the root context via unspecified vectors.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
RHSA-2012:1012
vendor-advisory
x_refsource_REDHAT
RHSA-2012:1166
vendor-advisory
x_refsource_REDHAT
RHSA-2012:1052
vendor-advisory
x_refsource_REDHAT
RHSA-2012:1053
vendor-advisory
x_refsource_REDHAT
https://issues.jboss.org/browse/MODCLUSTER-253
x_refsource_CONFIRM
49636
third-party-advisory
x_refsource_SECUNIA
https://bugzilla.redhat.com/show_bug.cgi?id=802200
x_refsource_MISC
RHSA-2012:1010
vendor-advisory
x_refsource_REDHAT
RHSA-2012:1011
vendor-advisory
x_refsource_REDHAT
https://community.jboss.org/message/624018
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now