CVE-2023-41081: Apache Tomcat Connectors: Unexpected use of first declared worker in mod_jk for unmapped request

Published Sep 13, 2023
·
Updated

Important: Authentication Bypass CVE-2023-41081

The modjk component of Apache Tomcat Connectors in some circumstances, such as when a configuration included "JkOptions +ForwardDirectories" but the configuration did not provide explicit mounts for all possible proxied requests, modjk would use an implicit mapping and map the request to the first defined worker. Such an implicit mapping could result in the unintended exposure of the status worker and/or bypass security constraints configured in httpd. As of JK 1.2.49, the implicit mapping functionality has been removed and all mappings must now be via explicit configuration. Only modjk is affected by this issue. The ISAPI redirector is not affected.

This issue affects Apache Tomcat Connectors (modjk only): from 1.2.0 through 1.2.48.

Users are recommended to upgrade to version 1.2.49, which fixes the issue.

History 2023-09-13 Original advisory

2023-09-28 Updated summary

Other sources

The modjk component of Apache Tomcat Connectors in some circumstances, such as when a configuration included "JkOptions +ForwardDirectories" but the configuration did not provide explicit mounts for all possible proxied requests, modjk would use an implicit mapping and map the request to the first defined worker. Such an implicit mapping could result in the unintended exposure of the status worker and/or bypass security constraints configured in httpd. As of JK 1.2.49, the implicit mapping functionality has been removed and all mappings must now be via explicit configuration. Only modjk is affected by this issue. The ISAPI redirector is not affected.

This issue affects Apache Tomcat Connectors (modjk only): from 1.2.0 through 1.2.48.

Users are recommended to upgrade to version 1.2.49, which fixes the issue.

https://lists.apache.org/thread/rd1r26w7271jyqgzr4492tooyt583d8b

Red Hat

Affected Software

9 affected componentsFixes available
Apache Tomcat Connectors>=1.2.0<1.2.49
ubuntu/libapache-mod-jk<1:1.2.43-1ubuntu0.1~
1:1.2.43-1ubuntu0.1~
ubuntu/libapache-mod-jk<1:1.2.46-1ubuntu0.1
1:1.2.46-1ubuntu0.1
ubuntu/libapache-mod-jk<1:1.2.48-1ubuntu0.1
1:1.2.48-1ubuntu0.1
ubuntu/libapache-mod-jk<1:1.2.48-2ubuntu0.1
1:1.2.48-2ubuntu0.1
ubuntu/libapache-mod-jk<1.2.49
1.2.49
ubuntu/libapache-mod-jk<1:1.2.41-1ubuntu0.1~
1:1.2.41-1ubuntu0.1~
debian/libapache-mod-jk
1:1.2.48-1+deb11u11:1.2.48-2+deb12u11:1.2.49-1
redhat/httpd<1.2.49
1.2.49

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade ubuntu/libapache-mod-jk to a version that resolves this vulnerability.

    Fixed in 1:1.2.43-1ubuntu0.1~
  2. Upgrade

    Upgrade ubuntu/libapache-mod-jk to a version that resolves this vulnerability.

    Fixed in 1:1.2.46-1ubuntu0.1
  3. Upgrade

    Upgrade ubuntu/libapache-mod-jk to a version that resolves this vulnerability.

    Fixed in 1:1.2.48-1ubuntu0.1
  4. Upgrade

    Upgrade ubuntu/libapache-mod-jk to a version that resolves this vulnerability.

    Fixed in 1:1.2.48-2ubuntu0.1
  5. Upgrade

    Upgrade ubuntu/libapache-mod-jk to a version that resolves this vulnerability.

    Fixed in 1.2.49
  6. Upgrade

    Upgrade ubuntu/libapache-mod-jk to a version that resolves this vulnerability.

    Fixed in 1:1.2.41-1ubuntu0.1~
  7. Upgrade

    Upgrade debian/libapache-mod-jk to a version that resolves this vulnerability.

    Fixed in 1:1.2.48-1+deb11u1Fixed in 1:1.2.48-2+deb12u1Fixed in 1:1.2.49-1
  8. Upgrade

    Upgrade redhat/httpd to a version that resolves this vulnerability.

    Fixed in 1.2.49
  9. Upgrade

    Upgrade Apache Tomcat Connectors (mod_jk) to a version that resolves this vulnerability.

    Fixed in 1.2.49Patch CVE-2023-41081
  10. Configuration

    Ensure all mod_jk request mappings are configured explicitly (implicit mapping behavior was removed as of JK 1.2.49; configure explicit mounts for all possible proxied requests instead of relying on implicit mapping).

    Apache Tomcat Connectors (mod_jk) Implicit mapping via first declared worker for unmapped request = removed / not used

Event History

Sep 13, 2023
CVE Published
via Ubuntu·12:00 AM
CVE Published
via MITRE·09:30 AM
Data Sourced
via MITRE·09:30 AM
DescriptionWeakness
Data Sourced
via Red Hat·08:53 PM
DescriptionSeverityAffected Software
Jun 11, 2024
Data Sourced
via Launchpad·04:16 PM
Description

Parent advisories

This vulnerability appears in the following advisories.

Frequently Asked Questions

1

What is the severity of CVE-2023-41081?

CVE-2023-41081 is classified as an Important vulnerability.

2

How do I fix CVE-2023-41081?

To fix CVE-2023-41081, upgrade Apache Tomcat Connectors to version 1.2.49 or the specific patched versions for your distribution.

3

What components are affected by CVE-2023-41081?

CVE-2023-41081 affects the mod_jk component of Apache Tomcat Connectors.

4

Can CVE-2023-41081 lead to unauthorized access?

Yes, CVE-2023-41081 can result in an authentication bypass allowing unauthorized access.

5

Which versions of Apache Tomcat Connectors are vulnerable to CVE-2023-41081?

Versions of Apache Tomcat Connectors prior to 1.2.49 are vulnerable to CVE-2023-41081.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203