SUSE-SU-2018:3970-1
Dashboard / Vulnerabilities / SUSE-SU-2018:3970-1
SUSE-SU-2018:3970-1
Summary: Security update for apache2-mod_jk
Details: This update for apache2-mod_jk fixes the following issues: Security issues fixed: - CVE-2018-11759: Fixed connector path traversal due to mishandled HTTP requests in httpd (bsc#1114612). - CVE-2014-8111: Apache Tomcat Connectors (mod_jk) ignored JkUnmount rules for subtrees of previous JkMount rules, which allowed remote attackers to access otherwise restricted artifacts via unspecified vectors (bsc#927845).
References: https://www.suse.com/support/update/announcement/2018/suse-su-20183970-1/, https://bugzilla.suse.com/1114612, https://bugzilla.suse.com/927845, https://www.suse.com/security/cve/CVE-2014-8111, https://www.suse.com/security/cve/CVE-2018-11759
Affected packages
Package
Name: apache2-mod_jk
Purl: pkg:rpm/suse/apache2-mod_jk&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4
Affected ranges
Type: ECOSYSTEM
Events:
