{"schema_version":"1.7.3","id":"SUSE-SU-2023:4513-1","published":"2023-11-21T16:25:57Z","modified":"2025-05-02T04:29:52.107435Z","related":["CVE-2018-11759"],"upstream":["CVE-2018-11759"],"summary":"Security update for apache2-mod_jk","details":"This update for apache2-mod_jk fixes the following issues:\n\nUpdate to version 1.2.49:\n  Apache\n    * Retrieve default request id from mod_unique_id. It can also be\n      taken from an arbitrary environment variable by configuring\n      'JkRequestIdIndicator'.\n    * Don't delegate the generatation of the response body to httpd\n      when the status code represents an error if the request used\n      the HEAD method.\n    * Only export the main module symbol. Visibility of module \n      internal symbols led to crashes when conflicting with library\n      symbols. Based on a patch provided by Josef Čejka.\n    * Remove support for implicit mapping of requests to workers. \n      All mappings must now be explicit.\n  IIS\n    * Set default request id as a GUID. It can also be taken from an\n      arbitrary request header by configuring 'request_id_header'.\n    * Fix non-empty check for the Translate header.\n  Common\n    * Fix compiler warning when initializing and copying fixed \n      length strings.\n    * Add a request id to mod_jk log lines.\n    * Enable configure to find the correct sizes for pid_t and \n      pthread_t when building on MacOS.\n    * Fix Clang 15/16 compatability. Pull request #6 provided by \n      Sam James.\n    * Improve XSS hardening in status worker.\n    * Add additional bounds and error checking when reading AJP \n      messages.\n  Docs\n    * Remove support for the Netscape / Sun ONE / Oracle iPlanet Web\n      Server as the product has been retired.\n    * Remove links to the old JK2 documentation. The JK2 \n      documentation is still available, it is just no longer linked\n      from the current JK documentation.\n    * Restructure subsections in changelog starting with version \n      1.2.45.\n\nChanges for 1.2.47 and 1.2.48 updates:\n  * Add: Apache: Extend trace level logging of method entry/exit to\n    aid debugging of request mapping issues.\n  * Fix: Apache: Fix a bug in the normalization checks that prevented\n    file based requests, such as SSI file includes, from being processed.\n  * Fix: Apache: When using JkAutoAlias, ensure that files that include\n    spaces in their name are accessible.\n  * Update: Common: Update the documentation to reflect that the source\n    code for the Apache Tomcat Connectors has moved from Subversion to Git.\n  * Fix: Common: When using set_session_cookie, ensure that an updated session\n    cookie is issued if the load-balancer has to failover to a different worker.\n  * Update: Common: Update config.guess and config.sub from\n    https://git.savannah.gnu.org/git/config.git.\n  * Update: Common: Update release script for migration to git.\n\nUpdate to version 1.2.46\n  Fixes:\n    * Apache: Fix regression in 1.2.44 which resulted in\n      socket_connect_timeout to be interpreted in units of seconds\n      instead of milliseconds on platforms that provide poll(). (rjung)\n    * Security: CVE-2018-11759 Connector path traversal [bsc#1114612]\n\nUpdate to version 1.2.45\n  Fixes:\n    * Correct regression in 1.2.44 that broke request handling for\n      OPTIONS * requests. (rjung)\n    * Improve path parameter parsing so that the session ID specified\n      by the session_path worker property for load-balanced workers\n      can be extracted from a path parameter in any segment of the\n      URI, rather than only from the final segment. (markt)\n    * Apache: Improve path parameter handling so that JkStripSession\n      can remove session IDs that are specified on path parameters in any\n      segment of the URI rather than only the final segment. (markt)\n    * IIS: Improve path parameter handling so that strip_session can\n      remove session IDs that are specified on path parameters in any\n      segment of the URI rather than only the final segment. (markt) \n  Updates:\n    * Apache: Update the documentation to note additional\n      limitations of the JkAutoAlias directive. (markt)\n  Code:\n    * Common: Optimize path parameter handling. (rjung)\n\nUpdate to version 1.2.44\n  Updates:\n    * Remove the Novell Netware make files and Netware specific source\n      code since there has not been a supported version of Netware\n      available for over five years. (markt)\n    * Apache: Update the documentation to use httpd 2.4.x style access\n      control directives. (markt)\n    * Update PCRE bundled with the ISAPI redirector to 8.42. (rjung)\n    * Update config.guess and config.sub from\n      https://git.savannah.gnu.org/git/config.git. (rjung)\n  Fixes:\n    * Common: Use Local, rather than Global, mutexs on Windows to\n      better support multi-user environments. (markt)\n    * Apache: Use poll rather than select to avoid the limitations of\n      select triggering an httpd crash. Patch provided by Koen Wilde. (markt)\n    * ISAPI: Remove the check that rejects requests that contain path\n      segments that match WEB-INF or META-INF as it duplicates a check\n      that Tomcat performs and, because ISAPI does not have visibility of\n      the current context path, it is impossible to implement this check\n      without valid requests being rejected. (markt)\n    * Refactor normalisation of request URIs to a common location and align\n      the normalisation implementation for mod_jk with that implemented by\n      Tomcat. (markt)\n  Add:\n    * Clarify the behvaiour of lb workers when all ajp13 workers fail with\n      particular reference to the role of the retries attribute. (markt)\n    * Add the new load-balancer worker property lb_retries to improve the\n      control over the number of retries. Based on a patch provided by\n      Frederik Nosi. (markt)\n    * Add a note to the documentation that the CollapseSlashes options are\n      now effectively hard-coded to CollpaseSlashesAll due to the changes\n      made to align normalization with that implemented in Tomcat. (markt)\n","affected":[{"package":{"name":"apache2-mod_jk","ecosystem":"SUSE:Linux Enterprise Module for Server Applications 15 SP4","purl":"pkg:rpm/suse/apache2-mod_jk&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.2.49-150100.6.6.1"}]}],"ecosystem_specific":{"binaries":[{"apache2-mod_jk":"1.2.49-150100.6.6.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:4513-1.json"}},{"package":{"name":"apache2-mod_jk","ecosystem":"SUSE:Linux Enterprise Module for Server Applications 15 SP5","purl":"pkg:rpm/suse/apache2-mod_jk&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.2.49-150100.6.6.1"}]}],"ecosystem_specific":{"binaries":[{"apache2-mod_jk":"1.2.49-150100.6.6.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:4513-1.json"}},{"package":{"name":"apache2-mod_jk","ecosystem":"openSUSE:Leap 15.4","purl":"pkg:rpm/opensuse/apache2-mod_jk&distro=openSUSE%20Leap%2015.4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.2.49-150100.6.6.1"}]}],"ecosystem_specific":{"binaries":[{"apache2-mod_jk":"1.2.49-150100.6.6.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:4513-1.json"}},{"package":{"name":"apache2-mod_jk","ecosystem":"openSUSE:Leap 15.5","purl":"pkg:rpm/opensuse/apache2-mod_jk&distro=openSUSE%20Leap%2015.5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.2.49-150100.6.6.1"}]}],"ecosystem_specific":{"binaries":[{"apache2-mod_jk":"1.2.49-150100.6.6.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:4513-1.json"}}],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2023/suse-su-20234513-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1114612"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-11759"}]}