CVE-2012-1154
Summary
| CVE | CVE-2012-1154 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2012-10-22 23:55:05 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | mod_cluster 1.0.10 before 1.0.10 CP03 and 1.1.x before 1.1.4, as used in JBoss Enterprise Application Platform 5.1.2, when "ROOT" is set to excludedContexts, exposes the root context of the server, which allows remote attackers to bypass access restrictions and gain access to applications deployed on the root context via unspecified vectors. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:M/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Redhat | Jboss Enterprise Application Platform | 5.1.2 | All | All | All |
| Application | Redhat | Mod Cluster | 1.0.10 | All | All | All |
| Application | Redhat | Mod Cluster | 1.1.0 | All | All | All |
| Application | Redhat | Mod Cluster | 1.1.1 | All | All | All |
| Application | Redhat | Mod Cluster | 1.1.2 | All | All | All |
| Application | Redhat | Mod Cluster | 1.1.3 | All | All | All |
| Application | Redhat | Mod Cluster | 1.1.4 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| ROOT ignored in excludedContexts| JBoss.org Content Archive (Read Only) | af854a3a-2127-422b-91ae-364da2661108 | community.jboss.org | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| Security Advisory SA49636 - Red Hat update for JBoss Enterprise Products - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| rhn.redhat.com/errata/RHSA-2012-1011.html | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| 802200 – (CVE-2012-1154) CVE-2012-1154 mod_cluster registers and exposes the root context of a server by default, despite ROOT being in the excluded-contexts list | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| [MODCLUSTER-253] ROOT in excludedContexts doesn't work - Red Hat Issue Tracker | af854a3a-2127-422b-91ae-364da2661108 | issues.jboss.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.