JBoss AS may expose root content if excluded-contexts list is mismatched
High severity
GitHub Reviewed
Published
Apr 23, 2022
to the GitHub Advisory Database
•
Updated Feb 2, 2023
Package
Affected versions
>= 7.0.0.Alpha1, < 7.1.1.Final
Patched versions
7.1.1.Final
Description
Published by the National Vulnerability Database
Mar 10, 2020
Published to the GitHub Advisory Database
Apr 23, 2022
Reviewed
Nov 22, 2022
Last updated
Feb 2, 2023
JBoss AS 7 prior to 7.1.1 and mod_cluster do not handle default hostname in the same way, which can cause the excluded-contexts list to be mismatched and the root context to be exposed.
References