Back

MEDIUM

mod_jk sends decoded URL to tomcat

Published May 25, 2007

Description

mod_jk in Apache Tomcat JK Web Server Connector 1.2.x before 1.2.23 decodes request URLs within the Apache HTTP Server before passing the URL to Tomcat, which allows remote attackers to access protected pages via a crafted prefix JkMount, possibly involving double-encoded .. (dot dot) sequences and directory traversal, a related issue to CVE-2007-0450.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (38)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published May 25, 2007
Updated Aug 7, 2024
Reserved Apr 4, 2007
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Important
Public date May 21, 2007