Apache Security Update – 14 September 2023

Apache has released a security update to address a vulnerability in Apache Tomcat Connectors.

The addressed vulnerability could allow the remote attacker to obtain sensitive information caused by a flaw in the mod_jk component by sending a specially crafted HTTP request.

Apache Tomcat Connectors Information Disclosure (CVE-2023-41081):

  • CVSS: 7.5
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Obtain Information
Vulnerabilities

CVE-2023-41081

Mitigations

The enterprise should deploy the patches as soon as the testing phase is
completed.

Apache Tomcat Connectors

References