CVE-2024-46544

CVE-2024-46544: Apache Tomcat Connectors: mod_jk: local users can view and modify configuration

Vendor Apache Software Foundation
Product Apache Tomcat Connectors
Weakness CWE-276
Published September 23, 2024
Last update October 31, 2024

CVSS base score

What the vulnerability does

Description

Incorrect Default Permissions vulnerability in Apache Tomcat Connectors allows local users to view and modify shared memory containing mod_jk configuration which may lead to information disclosure and/or denial of service. This issue affects Apache Tomcat Connectors: from 1.2.9-beta through 1.2.49. Only mod_jk on Unix like systems is affected. Neither the ISAPI redirector nor mod_jk on Windows is affected. Users are recommended to upgrade to version 1.2.50, which fixes the issue.

Key dates

Disclosure timeline

September 23, 2024 CVE published
October 31, 2024 Record updated