Back

HIGH

mod_cluster registers and exposes the root context of a JBoss AS 7 server by default, despite ROOT being in the excluded-contexts list

Published Mar 10, 2020

Description

JBoss AS 7 prior to 7.1.1 and mod_cluster do not handle default hostname in the same way, which can cause the excluded-contexts list to be mismatched and the root context to be exposed.

Affected products

Remediation

Red Hat statement

Not vulnerable. This issue only affects community JBoss AS 7 prior to 7.1.1. It does not affect components shipped with any Red Hat products.

Metrics

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Mar 10, 2020
Updated Aug 6, 2024
Reserved Feb 14, 2012
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Moderate
Public date Feb 4, 2012
GHSA-WQ8G-HM94-5RQQ