<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T03:52:19.050718+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2024:2387</id>
    <title>ALSA-2024:2387 — Moderate: mod_jk and mod_proxy_cluster security update</title>
    <updated>2026-10-05T03:52:19.244757+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: mod_jk, AlmaLinux:9: mod_proxy_cluster</p>
<p>The mod_jk module is a plugin for the Apache HTTP Server to connect it with the Apache Tomcat servlet engine.</p>
<p>The mod_proxy_cluster module is a plugin for the Apache HTTP Server that provides load-balancer functionality.</p>
<p>Security Fix(es):</p>
<p>* httpd: Apache Tomcat Connectors (mod_jk) Information Disclosure (CVE-2023-41081)
* mod_cluster/mod_proxy_cluster: Stored Cross site Scripting (CVE-2023-6710)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p>
<p>Additional Changes:</p>
<p>For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2024:2387"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2023-05818</id>
    <title>bdu:2023-05818</title>
    <updated>2026-10-05T03:52:19.244829+00:00</updated>
    <content>bdu:2023-05818</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2023-05818"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-188186</id>
    <title>EUVD-2026-188186</title>
    <updated>2026-10-05T03:52:19.244866+00:00</updated>
    <content>EUVD-2026-188186</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-188186"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-41081</id>
    <title>fkie_cve-2023-41081</title>
    <updated>2026-10-05T03:52:19.244881+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Important: Authentication Bypass CVE-2023-41081</p>
<p>The mod_jk component of Apache Tomcat Connectors in some circumstances, such as when a configuration included "JkOptions +ForwardDirectories" but the configuration did not       provide explicit mounts for all possible proxied requests, mod_jk would       use an implicit mapping and map the request to the first defined worker. Such an implicit mapping could result in the unintended exposure of the status worker and/or bypass security constraints configured in httpd. As of JK 1.2.49, the implicit mapping functionality has been removed and all mappings must now be via explicit configuration. Only mod_jk is affected by this issue. The ISAPI redirector is not affected.</p>
<p>This issue affects Apache Tomcat Connectors (mod_jk only): from 1.2.0 through 1.2.48.</p>
<p>Users are recommended to upgrade to version 1.2.49, which fixes the issue.</p>
<p>History
2023-09-13 Original advisory</p>
<p>2023-09-28 Updated summary</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-41081"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-4wvr-fq5p-2362</id>
    <title>GHSA-4wvr-fq5p-2362</title>
    <updated>2026-10-05T03:52:19.244916+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>The mod_jk component of Apache Tomcat Connectors in some circumstances, such as when a configuration included "JkOptions +ForwardDirectories" but the configuration did not       provide explicit mounts for all possible proxied requests, mod_jk would       use an implicit mapping and map the request to the first defined worker. Such an implicit mapping could result in the unintended exposure of the status worker and/or bypass security constraints configured in httpd. As of JK 1.2.49, the implicit mapping functionality has been removed and all mappings must now be via explicit configuration. Only mod_jk is affected by this issue. The ISAPI redirector is not affected.</p>
<p>This issue affects Apache Tomcat Connectors (mod_jk only): from 1.2.0 through 1.2.48.</p>
<p>Users are recommended to upgrade to version 1.2.49, which fixes the issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-4wvr-fq5p-2362"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-41081</id>
    <title>gsd-2023-41081</title>
    <updated>2026-10-05T03:52:19.244939+00:00</updated>
    <content>gsd-2023-41081</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-41081"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2023:7625</id>
    <title>RHSA-2023:7625 — Red Hat Security Advisory: Red Hat JBoss Core Services Apache HTTP Server 2.4.57 SP2 security update</title>
    <updated>2026-10-05T03:52:19.244950+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>openssl: Denial of service by excessive resource usage in verifying X509 policy constraints openssl: Invalid certificate policies in leaf certificates are silently ignored openssl: Certificate policy check not enabled openssl: Possible DoS translating ASN.1 object identifiers openssl: Excessive time spent checking DH keys and parameters OpenSSL: Excessive time spent checking DH q parameter value curl: out of heap memory issue due to missing limit on header quantity curl: heap based buffer overflow in the SOCKS5 proxy handshake curl: cookie injection with none file httpd: Apache Tomcat Connectors (mod_jk) Information Disclosure mod_http2: reset requests exhaust memory (incomplete fix of CVE-2023-44487)</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2023:7625"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2024:2387</id>
    <title>RHSA-2024:2387 — Red Hat Security Advisory: mod_jk and mod_proxy_cluster security update</title>
    <updated>2026-10-05T03:52:19.244983+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>mod_cluster/mod_proxy_cluster: Stored Cross site Scripting httpd: Apache Tomcat Connectors (mod_jk) Information Disclosure</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2024:2387"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2024:1198-1</id>
    <title>SUSE-SU-2024:1198-1 — Security update for apache2-mod_jk</title>
    <updated>2026-10-05T03:52:19.245000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for apache2-mod_jk</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2024:1198-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-41081</id>
    <title>UBUNTU-CVE-2023-41081</title>
    <updated>2026-10-05T03:52:19.245015+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: libapache-mod-jk, Ubuntu:Pro:18.04:LTS: libapache-mod-jk, Ubuntu:20.04:LTS: libapache-mod-jk, Ubuntu:22.04:LTS: libapache-mod-jk</p>
<p>Important: Authentication Bypass CVE-2023-41081 The mod_jk component of Apache Tomcat Connectors in some circumstances, such as when a configuration included "JkOptions +ForwardDirectories" but the configuration did not       provide explicit mounts for all possible proxied requests, mod_jk would       use an implicit mapping and map the request to the first defined worker. Such an implicit mapping could result in the unintended exposure of the status worker and/or bypass security constraints configured in httpd. As of JK 1.2.49, the implicit mapping functionality has been removed and all mappings must now be via explicit configuration. Only mod_jk is affected by this issue. The ISAPI redirector is not affected. This issue affects Apache Tomcat Connectors (mod_jk only): from 1.2.0 through 1.2.48. Users are recommended to upgrade to version 1.2.49, which fixes the issue. History 2023-09-13 Original advisory 2023-09-28 Updated summary</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-41081"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2337</id>
    <title>WID-SEC-W-2023-2337 — Apache Tomcat mod_jk Connector: Schwachstelle ermöglicht Umgehung von Sicherheitsmaßnahmen oder Offenlegung von Informa…</title>
    <updated>2026-10-05T03:52:19.245045+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter anonymer Angreifer kann eine Schwachstelle in Apache Tomcat mod_jk Connector ausnutzen, um Sicherheitsmaßnahmen zu umgehen oder vertrauliche Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2337"/>
  </entry>
</feed>
