CVE-2008-5519
libapache-mod-jk - information
EPSS 7.3%
描述
The JK Connector (aka mod_jk) 1.2.0 through 1.2.26 in Apache Tomcat allows remote attackers to obtain sensitive information via an arbitrary request from an HTTP client, in opportunistic circumstances involving (1) a request from a different client that included a Content-Length header but no POST data or (2) a rapid series of requests, related to noncompliance with the AJP protocol's requirements for requests containing Content-Length headers.
如何修補 CVE-2008-5519
要修補 CVE-2008-5519,請將受影響套件升級到下列已修補版本。
- Debian/libapache-mod-jk—升級至 1:1.2.26-2.1 或更新版本
- —升級至 1:1.2.18-3etch2 或更新版本
CVE-2008-5519 正在被利用嗎?
中等 — EPSS 為 7.3%,可持續追蹤但非最高優先。
受影響套件(2)
- from 0, < 1:1.2.26-2.1
- from 0, < 1:1.2.18-3etch2