Debian Package Tracker
Register | Log in
Subscribe

libapache-mod-jk

Choose email to subscribe with

general
  • source: libapache-mod-jk (main)
  • version: 1:1.2.49-1
  • maintainer: Debian Java Maintainers (archive) (DMD)
  • uploaders: Markus Koschany [DMD]
  • arch: all any
  • std-ver: 4.6.2
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 1:1.2.46-1+deb10u1
  • o-o-sec: 1:1.2.46-1+deb10u2
  • oldstable: 1:1.2.48-1
  • old-p-u: 1:1.2.48-1+deb11u1
  • stable: 1:1.2.48-2
  • stable-p-u: 1:1.2.48-2+deb12u1
  • testing: 1:1.2.49-1
  • unstable: 1:1.2.49-1
versioned links
  • 1:1.2.46-1+deb10u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1:1.2.46-1+deb10u2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1:1.2.48-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1:1.2.48-1+deb11u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1:1.2.48-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1:1.2.48-2+deb12u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1:1.2.49-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • libapache-mod-jk-doc
  • libapache2-mod-jk (1 bugs: 0, 1, 0, 0)
action needed
Multiarch hinter reports 1 issue(s) low
There are issues with the multiarch metadata for this package.
  • libapache-mod-jk-doc could be marked Multi-Arch: foreign
Created: 2016-09-14 Last update: 2023-10-03 21:07
1 low-priority security issue in bullseye low

There is 1 open security issue in bullseye.

1 issue left for the package maintainer to handle:
  • CVE-2023-41081: (needs triaging) Important: Authentication Bypass CVE-2023-41081 The mod_jk component of Apache Tomcat Connectors in some circumstances, such as when a configuration included "JkOptions +ForwardDirectories" but the configuration did not provide explicit mounts for all possible proxied requests, mod_jk would use an implicit mapping and map the request to the first defined worker. Such an implicit mapping could result in the unintended exposure of the status worker and/or bypass security constraints configured in httpd. As of JK 1.2.49, the implicit mapping functionality has been removed and all mappings must now be via explicit configuration. Only mod_jk is affected by this issue. The ISAPI redirector is not affected. This issue affects Apache Tomcat Connectors (mod_jk only): from 1.2.0 through 1.2.48. Users are recommended to upgrade to version 1.2.49, which fixes the issue. History 2023-09-13 Original advisory 2023-09-28 Updated summary

You can find information about how to handle this issue in the security team's documentation.

Created: 2023-09-14 Last update: 2023-09-30 06:14
debian/patches: 1 patch to forward upstream low

Among the 2 debian patches available in version 1:1.2.49-1 of the package, we noticed the following issues:

  • 1 patch where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2023-02-26 Last update: 2023-09-15 07:41
news
[rss feed]
  • [2023-09-24] Accepted libapache-mod-jk 1:1.2.48-1+deb11u1 (source) into oldstable-proposed-updates (Debian FTP Masters) (signed by: Markus Koschany)
  • [2023-09-24] Accepted libapache-mod-jk 1:1.2.48-2+deb12u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Markus Koschany)
  • [2023-09-24] Accepted libapache-mod-jk 1:1.2.46-1+deb10u2 (source) into oldoldstable (Markus Koschany)
  • [2023-09-17] libapache-mod-jk 1:1.2.49-1 MIGRATED to testing (Debian testing watch)
  • [2023-09-14] Accepted libapache-mod-jk 1:1.2.49-1 (source) into unstable (Markus Koschany)
  • [2023-03-01] libapache-mod-jk 1:1.2.48-2 MIGRATED to testing (Debian testing watch)
  • [2023-03-01] libapache-mod-jk 1:1.2.48-2 MIGRATED to testing (Debian testing watch)
  • [2023-03-01] libapache-mod-jk 1:1.2.48-2 MIGRATED to testing (Debian testing watch)
  • [2023-02-18] Accepted libapache-mod-jk 1:1.2.48-2 (source) into unstable (Markus Koschany)
  • [2023-02-11] libapache-mod-jk 1:1.2.48-1 MIGRATED to testing (Debian testing watch)
  • [2022-08-27] libapache-mod-jk REMOVED from testing (Debian testing watch)
  • [2020-06-13] Accepted libapache-mod-jk 1:1.2.46-1+deb10u1 (source) into proposed-updates->stable-new, proposed-updates (Debian FTP Masters) (signed by: Markus Koschany)
  • [2020-06-10] libapache-mod-jk 1:1.2.48-1 MIGRATED to testing (Debian testing watch)
  • [2020-06-04] Accepted libapache-mod-jk 1:1.2.48-1 (source) into unstable (Markus Koschany)
  • [2020-06-02] libapache-mod-jk 1:1.2.46-2 MIGRATED to testing (Debian testing watch)
  • [2020-05-27] Accepted libapache-mod-jk 1:1.2.46-2 (source) into unstable (Markus Koschany)
  • [2018-12-21] Accepted libapache-mod-jk 1:1.2.46-0+deb9u1 (source) into proposed-updates->stable-new, proposed-updates (Roberto C. Sanchez)
  • [2018-12-20] Accepted libapache-mod-jk 1:1.2.46-0+deb9u1 (source) into stable->embargoed, stable (Roberto C. Sanchez)
  • [2018-12-17] Accepted libapache-mod-jk 1:1.2.46-0+deb8u1 (source amd64 all) into oldstable (Roberto C. Sanchez)
  • [2018-10-19] libapache-mod-jk 1:1.2.46-1 MIGRATED to testing (Debian testing watch)
  • [2018-10-14] Accepted libapache-mod-jk 1:1.2.46-1 (source) into unstable (Markus Koschany)
  • [2018-10-11] libapache-mod-jk 1:1.2.44-3 MIGRATED to testing (Debian testing watch)
  • [2018-10-06] Accepted libapache-mod-jk 1:1.2.44-3 (source) into unstable (Markus Koschany)
  • [2018-10-03] Accepted libapache-mod-jk 1:1.2.44-2 (source) into unstable (Markus Koschany)
  • [2018-10-01] Accepted libapache-mod-jk 1:1.2.44-1 (source) into unstable (Markus Koschany)
  • [2018-03-18] libapache-mod-jk 1:1.2.43-1 MIGRATED to testing (Debian testing watch)
  • [2018-03-12] Accepted libapache-mod-jk 1:1.2.43-1 (source) into unstable (Emmanuel Bourg)
  • [2016-10-14] libapache-mod-jk 1:1.2.42-1 MIGRATED to testing (Debian testing watch)
  • [2016-10-08] Accepted libapache-mod-jk 1:1.2.42-1 (source) into unstable (Markus Koschany)
  • [2015-11-05] libapache-mod-jk 1:1.2.41-1 MIGRATED to testing (Britney)
  • 1
  • 2
bugs [bug history graph]
  • all: 3
  • RC: 0
  • I&N: 1
  • M&W: 2
  • F&P: 0
  • patch: 0
links
  • homepage
  • lintian
  • buildd: logs, reproducibility, cross
  • popcon
  • browse source code
  • edit tags
  • other distros
  • security tracker
  • debian patches
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 1:1.2.48-2
  • 7 bugs

Debian Package Tracker — Copyright 2013-2018 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing