VDB

MAGEIA-2015-254

MAGEIA-2015-254 PUBLISHED

An information disclosure flaw due to incorrect JkMount/JkUnmount directives processing was found in the Apache 2 module mod_jk to forward requests from the Apache web server to Tomcat. A JkUnmount rule for a subtree of a previous JkMount rule could be ignored. This could allow a remote attacker to potentially access a private artifact in a tree that would otherwise not be accessible to them (CVE-2014-8111).

Affected Products

VendorProductVersions
Mageiaapache-mod_jk1.2.37-6.2.mga4, 0

Timeline

  • Jul 1, 2015 CVE Published
  • Jul 9, 2015 CVE Updated
  • Mar 17, 2026 Distribution Patch
  • Mar 17, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›