CVE-2023-41081: Apache Tomcat Connectors: Unexpected use of first declared worker in mod_jk for unmapped request
Important: Authentication Bypass CVE-2023-41081
The modjk component of Apache Tomcat Connectors in some circumstances, such as when a configuration included "JkOptions +ForwardDirectories" but the configuration did not provide explicit mounts for all possible proxied requests, modjk would use an implicit mapping and map the request to the first defined worker. Such an implicit mapping could result in the unintended exposure of the status worker and/or bypass security constraints configured in httpd. As of JK 1.2.49, the implicit mapping functionality has been removed and all mappings must now be via explicit configuration. Only modjk is affected by this issue. The ISAPI redirector is not affected.
This issue affects Apache Tomcat Connectors (modjk only): from 1.2.0 through 1.2.48.
Users are recommended to upgrade to version 1.2.49, which fixes the issue.
History 2023-09-13 Original advisory
2023-09-28 Updated summary
Other sources
The modjk component of Apache Tomcat Connectors in some circumstances, such as when a configuration included "JkOptions +ForwardDirectories" but the configuration did not provide explicit mounts for all possible proxied requests, modjk would use an implicit mapping and map the request to the first defined worker. Such an implicit mapping could result in the unintended exposure of the status worker and/or bypass security constraints configured in httpd. As of JK 1.2.49, the implicit mapping functionality has been removed and all mappings must now be via explicit configuration. Only modjk is affected by this issue. The ISAPI redirector is not affected.
This issue affects Apache Tomcat Connectors (modjk only): from 1.2.0 through 1.2.48.
Users are recommended to upgrade to version 1.2.49, which fixes the issue.
https://lists.apache.org/thread/rd1r26w7271jyqgzr4492tooyt583d8b
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ubuntu/libapache-mod-jkto a version that resolves this vulnerability.Fixed in 1:1.2.43-1ubuntu0.1~ - Upgrade
Upgrade
ubuntu/libapache-mod-jkto a version that resolves this vulnerability.Fixed in 1:1.2.46-1ubuntu0.1 - Upgrade
Upgrade
ubuntu/libapache-mod-jkto a version that resolves this vulnerability.Fixed in 1:1.2.48-1ubuntu0.1 - Upgrade
Upgrade
ubuntu/libapache-mod-jkto a version that resolves this vulnerability.Fixed in 1:1.2.48-2ubuntu0.1 - Upgrade
Upgrade
ubuntu/libapache-mod-jkto a version that resolves this vulnerability.Fixed in 1.2.49 - Upgrade
Upgrade
ubuntu/libapache-mod-jkto a version that resolves this vulnerability.Fixed in 1:1.2.41-1ubuntu0.1~ - Upgrade
Upgrade
debian/libapache-mod-jkto a version that resolves this vulnerability.Fixed in 1:1.2.48-1+deb11u1Fixed in 1:1.2.48-2+deb12u1Fixed in 1:1.2.49-1 - Upgrade
Upgrade
redhat/httpdto a version that resolves this vulnerability.Fixed in 1.2.49 - Upgrade
Upgrade
Apache Tomcat Connectors (mod_jk)to a version that resolves this vulnerability.Fixed in 1.2.49Patch CVE-2023-41081 - Configuration
Ensure all mod_jk request mappings are configured explicitly (implicit mapping behavior was removed as of JK 1.2.49; configure explicit mounts for all possible proxied requests instead of relying on implicit mapping).
Apache Tomcat Connectors (mod_jk) Implicit mapping via first declared worker for unmapped request = removed / not used
Event History
Frequently Asked Questions
What is the severity of CVE-2023-41081?
CVE-2023-41081 is classified as an Important vulnerability.
How do I fix CVE-2023-41081?
To fix CVE-2023-41081, upgrade Apache Tomcat Connectors to version 1.2.49 or the specific patched versions for your distribution.
What components are affected by CVE-2023-41081?
CVE-2023-41081 affects the mod_jk component of Apache Tomcat Connectors.
Can CVE-2023-41081 lead to unauthorized access?
Yes, CVE-2023-41081 can result in an authentication bypass allowing unauthorized access.
Which versions of Apache Tomcat Connectors are vulnerable to CVE-2023-41081?
Versions of Apache Tomcat Connectors prior to 1.2.49 are vulnerable to CVE-2023-41081.