[ALSA-2024:2387] Moderate: mod_jk and mod_proxy_cluster security update
Type:
security
Severity:
moderate
Release date:
2024-05-07
Description:
The mod_jk module is a plugin for the Apache HTTP Server to connect it with the Apache Tomcat servlet engine. The mod_proxy_cluster module is a plugin for the Apache HTTP Server that provides load-balancer functionality. Security Fix(es): * httpd: Apache Tomcat Connectors (mod_jk) Information Disclosure (CVE-2023-41081) * mod_cluster/mod_proxy_cluster: Stored Cross site Scripting (CVE-2023-6710) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 mod_proxy_cluster-1.3.20-1.el9_4.aarch64.rpm 6bcb5a341b0d28ce6abf1c4b2b2e23921727a2ad71f8ef1705841a025f8f7964
aarch64 mod_jk-1.2.49-1.el9_4.aarch64.rpm c7b9d45d3262fae27d14ef1e5777334af6535036857f7a03512a2c5d3555ef14
ppc64le mod_proxy_cluster-1.3.20-1.el9_4.ppc64le.rpm 580ab82c6cc898a2c4bfefd6463cd27410c171c7b4baf7bb2df3d14c565273ce
ppc64le mod_jk-1.2.49-1.el9_4.ppc64le.rpm 85be7925f51cf1459b2992926971dac5924187e17887713b8285671a988d47f5
s390x mod_jk-1.2.49-1.el9_4.s390x.rpm 1dbf1bfbfc9c76b3feb16feb3854b21cec86a5cc24b2283265958db4b6b69ee9
s390x mod_proxy_cluster-1.3.20-1.el9_4.s390x.rpm 40ee496dba076c0a85cc45936df0df60274f659a9273e51d850d5a2e10800879
x86_64 mod_proxy_cluster-1.3.20-1.el9_4.x86_64.rpm 35350cd4fd41c369463c74b3b9b72d6d3dbffbca4bbc8848be605c8ecb83d5d1
x86_64 mod_jk-1.2.49-1.el9_4.x86_64.rpm 9e7df290242100f5cb64f3df512fb4cd171d531f3003bc842b69a64c60379209
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.