Bug 237656 (CVE-2007-1860)
| Summary: | CVE-2007-1860 mod_jk sends decoded URL to tomcat | ||||||
|---|---|---|---|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | Mark J. Cox <mjc> | ||||
| Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> | ||||
| Status: | CLOSED ERRATA | QA Contact: | |||||
| Severity: | medium | Docs Contact: | |||||
| Priority: | medium | ||||||
| Version: | unspecified | CC: | jclere, security-response-team | ||||
| Target Milestone: | --- | Keywords: | Security | ||||
| Target Release: | --- | ||||||
| Hardware: | All | ||||||
| OS: | Linux | ||||||
| Whiteboard: | |||||||
| Fixed In Version: | Doc Type: | Bug Fix | |||||
| Doc Text: | Story Points: | --- | |||||
| Clone Of: | Environment: | ||||||
| Last Closed: | 2010-05-11 08:57:30 UTC | Type: | --- | ||||
| Regression: | --- | Mount Type: | --- | ||||
| Documentation: | --- | CRM: | |||||
| Verified Versions: | Category: | --- | |||||
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |||||
| Cloudforms Team: | --- | Target Upstream Version: | |||||
| Embargoed: | |||||||
| Bug Depends On: | 237657, 237658, 240947, 242451, 430726, 430727, 449337 | ||||||
| Bug Blocks: | 444136 | ||||||
| Attachments: |
|
||||||
|
Description
Mark J. Cox
2007-04-24 15:06:36 UTC
Jean-Frederic said that "JkOptions ForwardURICompatUnparsed" should prevent the problem and mod_jk code should be changed to use it as default value. (The actual value ForwardURICompat breaks the spec's). (In reply to comment #1) > Jean-Frederic said that "JkOptions ForwardURICompatUnparsed" should prevent > the problem and mod_jk code should be changed to use it as default value. > (The actual value ForwardURICompat breaks the spec's). ForwardURICompat is the default option and can be overriden with something like JkOptions +ForwardURICompatUnparsed in the conf file. Note that we dont install a conf files for mod_jk - we have samples, so the change cant be made in the conf file. Our samples dont mention JkOptions either so customers using them will use the default. Is Jean-Frederic suggesting that the code be made to use ForwardURICompatUnparsed by default? Is there a patch for this? Note that documentation would need to be updated for this as well since most of it suggests that the default is ForwardURICompat. [Adding Jean-Frederic to CC list] JF - Can you take a look at the above and let me know what you think? Yes the mod_jk code should be made to use ForwardURICompatUnparsed by default. No there isn't a patch for the moment. (In reply to comment #4) > Yes the mod_jk code should be made to use ForwardURICompatUnparsed by default. > No there isn't a patch for the moment. Thanks for the clarification. Please update the BZ when a patch is available. Created attachment 154748 [details]
Patch for tomcat-connectors change the default value of JK_OPT_FWDURIDEFAUL
Patch for svn.apache.org/repos/asf/tomcat/connectors/trunk (15/05/2007).
It changes the default behaviour of mod_jk and have not yet been committed in
te ASF repos.
this is now public at http://tomcat.apache.org/security-jk.html, removing embargo |