Back

MEDIUM

mod_cluster registers and exposes the root context of a server by default, despite ROOT being in the excluded-contexts list

Published Oct 22, 2012

Description

mod_cluster 1.0.10 before 1.0.10 CP03 and 1.1.x before 1.1.4, as used in JBoss Enterprise Application Platform 5.1.2, when "ROOT" is set to excludedContexts, exposes the root context of the server, which allows remote attackers to bypass access restrictions and gain access to applications deployed on the root context via unspecified vectors.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (2)

References (14)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Oct 22, 2012
Updated Aug 6, 2024
Reserved Feb 14, 2012
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Moderate
Public date Aug 31, 2011
GHSA-V2FP-H4QX-X3R6