RLSA-2024:7457

Source
https://errata.rockylinux.org/RLSA-2024:7457
Import Source
https://storage.googleapis.com/resf-osv-data/RLSA-2024:7457.json
JSON Data
https://api.osv.dev/v1/vulns/RLSA-2024:7457
Published
2025-05-07T19:13:09.903227Z
Modified
2025-05-07T20:08:48.149588Z
Upstream
Severity
  • 5.9 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L CVSS Calculator
Summary
Moderate: mod_jk bug fix update
Details

The mod_jk module is an Apache HTTP Server plug-in that enables the Apache HTTP Server to connect with the Apache Tomcat servlet engine.

Bug Fix(es):

  • Rebase to upstream 1.2.50 release (JIRA:Rocky Linux-58855)

Security fix(es):

  • mod_jk: information Disclosure / DoS (CVE-2024-46544) (JIRA:Rocky Linux-59800)
References
Credits
    • Rocky Enterprise Software Foundation
    • Red Hat

Affected packages

Rocky Linux:9 / mod_jk

Package

Name
mod_jk
Purl
pkg:rpm/rocky-linux/mod_jk?distro=rocky-linux-9&epoch=0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0:1.2.50-1.el9_4.1