VYPR

Tomcat JK (mod_jk) Connector

by Apache

CVEs (1)

  • CVE-2018-11759HigOct 31, 2018
    risk 0.56cvss 7.5epss 0.91

    The Apache Web Server (httpd) specific code that normalised the requested path before matching it to the URI-worker map in Apache Tomcat JK (mod_jk) Connector 1.2.0 to 1.2.44 did not handle some edge cases correctly. If only a sub-set of the URLs supported by Tomcat were exposed…