Author: markt
Date: Mon Sep 23 10:40:16 2024
New Revision: 1920855

URL: http://svn.apache.org/viewvc?rev=1920855&view=rev
Log:
Add CVE-2024-46544

Modified:
    tomcat/site/trunk/docs/security-jk.html
    tomcat/site/trunk/xdocs/security-jk.xml

Modified: tomcat/site/trunk/docs/security-jk.html
URL: 
http://svn.apache.org/viewvc/tomcat/site/trunk/docs/security-jk.html?rev=1920855&r1=1920854&r2=1920855&view=diff
==============================================================================
--- tomcat/site/trunk/docs/security-jk.html (original)
+++ tomcat/site/trunk/docs/security-jk.html Mon Sep 23 10:40:16 2024
@@ -1,6 +1,6 @@
 <!DOCTYPE html SYSTEM "about:legacy-compat">
 <html lang="en"><head><META http-equiv="Content-Type" content="text/html; 
charset=UTF-8"><meta name="viewport" content="width=device-width, 
initial-scale=1"><link href="res/css/tomcat.css" rel="stylesheet" 
type="text/css"><link href="res/css/fonts/fonts.css" rel="stylesheet" 
type="text/css"><title>Apache Tomcat&reg; - Apache Tomcat JK Connectors 
vulnerabilities</title><meta name="author" content="Apache Tomcat 
Project"><script 
src="https://www.apachecon.com/event-images/snippet.js";></script></head><body><div
 id="wrapper"><header id="header"><div class="clearfix"><div 
class="menu-toggler pull-left" tabindex="1"><div 
class="hamburger"></div></div><a href="http://tomcat.apache.org/";><img 
class="tomcat-logo pull-left noPrint" alt="Tomcat Home" 
src="res/images/tomcat.png"></a><h1 class="pull-left">Apache 
Tomcat<sup>&reg;</sup></h1><div class="asf-logos pull-right"><a 
href="https://www.apache.org/foundation/contributing.html"; target="_blank" 
class="pull-left"><img src="https://www.apache.
 org/images/SupportApache-small.png" class="support-asf" alt="Support 
Apache"></a><a href="http://www.apache.org/"; target="_blank" 
class="pull-left"><img src="res/images/asf_logo.svg" class="asf-logo" alt="The 
Apache Software Foundation"></a></div></div></header><main 
id="middle"><div><div id="mainLeft"><div id="nav-wrapper"><form 
action="https://www.google.com/search"; method="get"><div 
class="searchbox"><input value="tomcat.apache.org" name="sitesearch" 
type="hidden"><input aria-label="Search text" placeholder="Search&hellip;" 
required="required" name="q" id="query" 
type="search"><button>GO</button></div></form><div class="asfevents"><a 
class="acevent" data-format="square" 
data-width="150"></a></div><nav><div><h2>Apache Tomcat</h2><ul><li><a 
href="./index.html">Home</a></li><li><a 
href="./taglibs.html">Taglibs</a></li><li><a href="./maven-plugin.html">Maven 
Plugin</a></li></ul></div><div><h2>Download</h2><ul><li><a 
href="./whichversion.html">Which version?</a></li><li><a href="https
 ://tomcat.apache.org/download-11.cgi">Tomcat 11 (beta)</a></li><li><a 
href="https://tomcat.apache.org/download-10.cgi";>Tomcat 10</a></li><li><a 
href="https://tomcat.apache.org/download-90.cgi";>Tomcat 9</a></li><li><a 
href="https://tomcat.apache.org/download-migration.cgi";>Tomcat Migration Tool 
for Jakarta EE</a></li><li><a 
href="https://tomcat.apache.org/download-connectors.cgi";>Tomcat 
Connectors</a></li><li><a 
href="https://tomcat.apache.org/download-native.cgi";>Tomcat 
Native</a></li><li><a 
href="https://tomcat.apache.org/download-taglibs.cgi";>Taglibs</a></li><li><a 
href="https://archive.apache.org/dist/tomcat/";>Archives</a></li></ul></div><div><h2>Documentation</h2><ul><li><a
 href="./tomcat-11.0-doc/index.html">Tomcat 11.0 (beta)</a></li><li><a 
href="./tomcat-10.1-doc/index.html">Tomcat 10.1</a></li><li><a 
href="./tomcat-9.0-doc/index.html">Tomcat 9.0</a></li><li><a 
href="./upgrading.html">Upgrading</a></li><li><a 
href="./connectors-doc/index.html">Tomcat Connectors</a></li><li><a
  href="./native-doc/index.html">Tomcat Native 2</a></li><li><a 
href="./native-1.3-doc/index.html">Tomcat Native 1.3</a></li><li><a 
href="https://cwiki.apache.org/confluence/display/TOMCAT";>Wiki</a></li><li><a 
href="./migration.html">Migration Guide</a></li><li><a 
href="./presentations.html">Presentations</a></li><li><a 
href="https://cwiki.apache.org/confluence/x/Bi8lBg";>Specifications</a></li></ul></div><div><h2>Problems?</h2><ul><li><a
 href="./security.html">Security Reports</a></li><li><a 
href="./findhelp.html">Find help</a></li><li><a 
href="https://cwiki.apache.org/confluence/display/TOMCAT/FAQ";>FAQ</a></li><li><a
 href="./lists.html">Mailing Lists</a></li><li><a href="./bugreport.html">Bug 
Database</a></li><li><a href="./irc.html">IRC</a></li></ul></div><div><h2>Get 
Involved</h2><ul><li><a href="./getinvolved.html">Overview</a></li><li><a 
href="./source.html">Source code</a></li><li><a 
href="./ci.html">Buildbot</a></li><li><a 
href="./tools.html">Tools</a></li></ul></div><div><h2>
 Media</h2><ul><li><a 
href="https://twitter.com/theapachetomcat";>Twitter</a></li><li><a 
href="https://www.youtube.com/c/ApacheTomcatOfficial";>YouTube</a></li><li><a 
href="https://blogs.apache.org/tomcat/";>Blog</a></li></ul></div><div><h2>Misc</h2><ul><li><a
 href="./whoweare.html">Who We Are</a></li><li><a 
href="https://www.redbubble.com/people/comdev/works/30885254-apache-tomcat";>Swag</a></li><li><a
 href="./heritage.html">Heritage</a></li><li><a 
href="http://www.apache.org";>Apache Home</a></li><li><a 
href="./resources.html">Resources</a></li><li><a 
href="./contact.html">Contact</a></li><li><a 
href="./legal.html">Legal</a></li><li><a 
href="https://privacy.apache.org/policies/privacy-policy-public.html";>Privacy</a></li><li><a
 href="https://www.apache.org/foundation/contributing.html";>Support 
Apache</a></li><li><a 
href="https://www.apache.org/foundation/sponsorship.html";>Sponsorship</a></li><li><a
 href="http://www.apache.org/foundation/thanks.html";>Thanks</a></li><li><a 
href="http://www
 .apache.org/licenses/">License</a></li></ul></div></nav></div></div><div 
id="mainRight"><div id="content"><h2 style="display: none;">Content</h2><h3 
id="Table_of_Contents">Table of Contents</h3><div class="text">
-<ul><li><a href="#Apache_Tomcat_JK_Connectors_vulnerabilities">Apache Tomcat 
JK Connectors vulnerabilities</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_JK_Connector_1.2.49">Fixed in Apache Tomcat JK 
Connector 1.2.49</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_JK_Connector_1.2.46">Fixed in Apache Tomcat JK 
Connector 1.2.46</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_JK_Connector_1.2.43">Fixed in Apache Tomcat JK 
Connector 1.2.43</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_JK_Connector_1.2.42">Fixed in Apache Tomcat JK 
Connector 1.2.42</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_JK_Connector_1.2.41">Fixed in Apache Tomcat JK 
Connector 1.2.41</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_JK_Connector_1.2.27">Fixed in Apache Tomcat JK 
Connector 1.2.27</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_JK_Connector_1.2.23">Fixed in Apache Tomcat JK 
Connector 1.2.23</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_JK_Connector_1.2.21">Fixed in Apache Tomcat JK 
Connector 1.2.21</a></li><li><a hre
 f="#Fixed_in_Apache_Tomcat_JK_Connector_1.2.16">Fixed in Apache Tomcat JK 
Connector 1.2.16</a></li></ul>
+<ul><li><a href="#Apache_Tomcat_JK_Connectors_vulnerabilities">Apache Tomcat 
JK Connectors vulnerabilities</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_JK_Connector_1.2.50">Fixed in Apache Tomcat JK 
Connector 1.2.50</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_JK_Connector_1.2.49">Fixed in Apache Tomcat JK 
Connector 1.2.49</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_JK_Connector_1.2.46">Fixed in Apache Tomcat JK 
Connector 1.2.46</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_JK_Connector_1.2.43">Fixed in Apache Tomcat JK 
Connector 1.2.43</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_JK_Connector_1.2.42">Fixed in Apache Tomcat JK 
Connector 1.2.42</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_JK_Connector_1.2.41">Fixed in Apache Tomcat JK 
Connector 1.2.41</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_JK_Connector_1.2.27">Fixed in Apache Tomcat JK 
Connector 1.2.27</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_JK_Connector_1.2.23">Fixed in Apache Tomcat JK 
Connector 1.2.23</a></li><li><a hre
 f="#Fixed_in_Apache_Tomcat_JK_Connector_1.2.21">Fixed in Apache Tomcat JK 
Connector 1.2.21</a></li><li><a 
href="#Fixed_in_Apache_Tomcat_JK_Connector_1.2.16">Fixed in Apache Tomcat JK 
Connector 1.2.16</a></li></ul>
 </div><h3 id="Apache_Tomcat_JK_Connectors_vulnerabilities">Apache Tomcat JK 
Connectors vulnerabilities</h3><div class="text">
     <p>This page lists all security vulnerabilities fixed in released versions
        of Apache Tomcat Jk Connectors. Each vulnerability is given a
@@ -15,6 +15,24 @@
        vulnerabilities to the <a href="security.html">Tomcat
        Security Team</a>.</p>
 
+  </div><h3 id="Fixed_in_Apache_Tomcat_JK_Connector_1.2.50">Fixed in Apache 
Tomcat JK Connector 1.2.50</h3><div class="text">
+    <p><strong>Moderate: Information disclosure / Denial of service</strong>
+       <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-46544"; 
rel="nofollow">CVE-2024-46544</a></p>
+
+    <p>Incorrect default permissions for the memory mapped file configured by
+       the <code>JkShmFile</code> directive on Unix like systems allows local
+       users to view and/or modify the contents of the shared memory containing
+       mod_jk configuration and status information. This could result in
+       information disclosure and/or denial of service.</p>
+
+    <p>This was fixed with commit
+       <a 
href="https://github.com/apache/tomcat-connectors/commit/d55706e92b65018c2e4c7ab14014a996b0174966";>d55706e9</a>.</p>
+
+    <p>This issue was identified by the Tomcat Security Team on 6 August 2024.
+       The issue was made public on 23 September 2024.</p>
+
+    <p>Affects: JK 1.2.9-1.2.49 (mod_jk on Unix like platforms only)</p>
+
   </div><h3 id="Fixed_in_Apache_Tomcat_JK_Connector_1.2.49">Fixed in Apache 
Tomcat JK Connector 1.2.49</h3><div class="text">
     <p><strong>Important: Information disclosure</strong>
        <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-41081"; 
rel="nofollow">CVE-2023-41081</a></p>

Modified: tomcat/site/trunk/xdocs/security-jk.xml
URL: 
http://svn.apache.org/viewvc/tomcat/site/trunk/xdocs/security-jk.xml?rev=1920855&r1=1920854&r2=1920855&view=diff
==============================================================================
--- tomcat/site/trunk/xdocs/security-jk.xml (original)
+++ tomcat/site/trunk/xdocs/security-jk.xml Mon Sep 23 10:40:16 2024
@@ -28,6 +28,26 @@
 
   </section>
 
+  <section name="Fixed in Apache Tomcat JK Connector 1.2.50">
+    <p><strong>Moderate: Information disclosure / Denial of service</strong>
+       <cve>CVE-2024-46544</cve></p>
+
+    <p>Incorrect default permissions for the memory mapped file configured by
+       the <code>JkShmFile</code> directive on Unix like systems allows local
+       users to view and/or modify the contents of the shared memory containing
+       mod_jk configuration and status information. This could result in
+       information disclosure and/or denial of service.</p>
+
+    <p>This was fixed with commit
+       <connectorshashlink 
hash="d55706e92b65018c2e4c7ab14014a996b0174966"/>.</p>
+
+    <p>This issue was identified by the Tomcat Security Team on 6 August 2024.
+       The issue was made public on 23 September 2024.</p>
+
+    <p>Affects: JK 1.2.9-1.2.49 (mod_jk on Unix like platforms only)</p>
+
+  </section>
+
   <section name="Fixed in Apache Tomcat JK Connector 1.2.49">
     <p><strong>Important: Information disclosure</strong>
        <cve>CVE-2023-41081</cve></p>



---------------------------------------------------------------------
To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org
For additional commands, e-mail: dev-h...@tomcat.apache.org

Reply via email to