Merge ~octagalland/ubuntu-cve-tracker:retire_cve_2023_41081 into ubuntu-cve-tracker:master

Proposed by Octavio Galland
Status: Merged
Merged at revision: 70f5696c7c0eeeb50978e484bf31c22a5efbed08
Proposed branch: ~octagalland/ubuntu-cve-tracker:retire_cve_2023_41081
Merge into: ubuntu-cve-tracker:master
Diff against target: 74 lines (+19/-13)
2 files modified
meta_lists/package_info_overrides.json (+4/-0)
retired/CVE-2023-41081 (+15/-13)
Reviewer Review Type Date Requested Status
Emilia Torino Approve
Review via email: mp+467301@code.launchpad.net

Commit message

retire CVE-2023-41081

Description of the change

retire CVE-2023-41081

To post a comment you must log in.
Revision history for this message
Emilia Torino (emitorino) wrote :

LGTM, thanks!

review: Approve

Preview Diff

[H/L] Next/Prev Comment, [J/K] Next/Prev File, [N/P] Next/Prev Hunk
1diff --git a/meta_lists/package_info_overrides.json b/meta_lists/package_info_overrides.json
2index b1c5230..fdc7e1f 100644
3--- a/meta_lists/package_info_overrides.json
4+++ b/meta_lists/package_info_overrides.json
5@@ -867,6 +867,10 @@
6 "description": "Lib3MF is a C++ implementation of the 3D Manufacturing Format",
7 "title": "lib3mf"
8 },
9+ "libapache-mod-jk": {
10+ "description": "Apache 2 connector for the Tomcat Java servlet engine",
11+ "title": "mod_jk"
12+ },
13 "libapache-session-ldap-perl": {
14 "description": "Apache::Session::LDAP Perl module - Store Apache Session in LDAP",
15 "title": "Apache::Session::LDAP"
16diff --git a/active/CVE-2023-41081 b/retired/CVE-2023-41081
17similarity index 72%
18rename from active/CVE-2023-41081
19rename to retired/CVE-2023-41081
20index 6168d28..7c89095 100644
21--- a/active/CVE-2023-41081
22+++ b/retired/CVE-2023-41081
23@@ -1,3 +1,4 @@
24+PublicDateAtUSN: 2023-09-13 10:15:00 UTC
25 Candidate: CVE-2023-41081
26 PublicDate: 2023-09-13 10:15:00 UTC
27 References:
28@@ -5,6 +6,7 @@ References:
29 http://www.openwall.com/lists/oss-security/2023/09/13/2
30 https://tomcat.apache.org/security-jk.html#Fixed_in_Apache_Tomcat_JK_Connector_1.2.49
31 https://www.cve.org/CVERecord?id=CVE-2023-41081
32+ https://ubuntu.com/security/notices/USN-6826-1
33 Description:
34 Important: Authentication Bypass CVE-2023-41081 The mod_jk component of
35 Apache Tomcat Connectors in some circumstances, such as when a
36@@ -25,25 +27,25 @@ Notes:
37 Mitigation:
38 Bugs:
39 Priority: medium
40-Discovered-by:
41-Assigned-to: octagalland
42+Discovered-by: Karl von Randow
43+Assigned-to:
44 CVSS:
45 nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N [7.5 HIGH]
46
47 Patches_libapache-mod-jk:
48 upstream: https://github.com/apache/tomcat-connectors/commit/0095b6cb84f41313ee4c0364b49c766168790792
49-upstream_libapache-mod-jk: needs-triage
50+upstream_libapache-mod-jk: released (1.2.49)
51 trusty_libapache-mod-jk: ignored (end of standard support)
52 xenial_libapache-mod-jk: ignored (end of standard support)
53-esm-apps/xenial_libapache-mod-jk: needed
54+esm-apps/xenial_libapache-mod-jk: released (1:1.2.41-1ubuntu0.1~esm1)
55 bionic_libapache-mod-jk: ignored (end of standard support)
56-esm-apps/bionic_libapache-mod-jk: needed
57-focal_libapache-mod-jk: needed
58-esm-apps/focal_libapache-mod-jk: needed
59-jammy_libapache-mod-jk: needed
60-esm-apps/jammy_libapache-mod-jk: needed
61+esm-apps/bionic_libapache-mod-jk: released (1:1.2.43-1ubuntu0.1~esm1)
62+focal_libapache-mod-jk: released (1:1.2.46-1ubuntu0.1)
63+esm-apps/focal_libapache-mod-jk: not-affected (1:1.2.46-1ubuntu0.1)
64+jammy_libapache-mod-jk: released (1:1.2.48-1ubuntu0.1)
65+esm-apps/jammy_libapache-mod-jk: not-affected (1:1.2.48-1ubuntu0.1)
66 lunar_libapache-mod-jk: ignored (end of life, was needed)
67-mantic_libapache-mod-jk: needed
68-noble_libapache-mod-jk: needed
69-esm-apps/noble_libapache-mod-jk: needed
70-devel_libapache-mod-jk: needed
71+mantic_libapache-mod-jk: released (1:1.2.48-2ubuntu0.1)
72+noble_libapache-mod-jk: not-affected (1:1.2.49-1)
73+esm-apps/noble_libapache-mod-jk: not-affected (1:1.2.49-1)
74+devel_libapache-mod-jk: not-affected (1:1.2.49-1build1)

Subscribers

People subscribed via source and target branches