Back

LOW

mod_jk: session information leak

Published Apr 9, 2009

Description

The JK Connector (aka mod_jk) 1.2.0 through 1.2.26 in Apache Tomcat allows remote attackers to obtain sensitive information via an arbitrary request from an HTTP client, in opportunistic circumstances involving (1) a request from a different client that included a Content-Length header but no POST data or (2) a rapid series of requests, related to noncompliance with the AJP protocol's requirements for requests containing Content-Length headers.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (29)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Apr 9, 2009
Updated Aug 7, 2024
Reserved Dec 12, 2008
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Important
Public date Oct 28, 2008