Apache Tomcat jk isapi Connector information leakage (CVE-2018-1323)
Apache Tomcat jk isapi Connector information leakage (CVE-2018-1323)
Release date:
Updated on:
Affected Systems:
Apache Group Tomcat jk isapi Connector 1.2.0-1.2.42
Description:
CVE (CAN) ID: CVE-2018-1323
Apache Tomcat is a popular open-source JSP application server program.
Apache Tomcat jk isapi Connector 1.2.0-1.2.42. If the specific IIS/ISAPI Code does not properly handle certain unexpected situations, attackers can access the application by proxy anyway.
<* Source: vendor
*>
Suggestion:
Vendor patch:
Apache Group
------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://lists.apache.org/thread.html/6e146bce83578bd870893250ba8354e28f9d8e86c674c30dbeee529f@%3Cannounce.tomcat.apache.org%3E
This article permanently updates link: https://www.bkjia.com/Linux/2018-03/151414.htm