Skip to content

Improper Access Control in JBoss mod_cluster

Moderate severity GitHub Reviewed Published May 17, 2022 to the GitHub Advisory Database • Updated Jan 30, 2023

Package

maven org.jboss.mod_cluster:mod_cluster (Maven)

Affected versions

>= 1.1.0, < 1.1.4

Patched versions

1.1.4

Description

mod_cluster 1.0.10 before 1.0.10 CP03 and 1.1.x before 1.1.4, as used in JBoss Enterprise Application Platform 5.1.2, when "ROOT" is set to excludedContexts, exposes the root context of the server, which allows remote attackers to bypass access restrictions and gain access to applications deployed on the root context via unspecified vectors.

References

Published by the National Vulnerability Database Oct 22, 2012
Published to the GitHub Advisory Database May 17, 2022
Reviewed Nov 1, 2022
Last updated Jan 30, 2023

Severity

Moderate

EPSS score

0.546%
(78th percentile)

Weaknesses

CVE ID

CVE-2012-1154

GHSA ID

GHSA-v2fp-h4qx-x3r6

Source code

No known source code
Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.