-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.jboss.mod_cluster:mod_cluster | maven | >= 1.1.0, < 1.1.4 | 1.1.4 |
The vulnerability stems from improper handling of the root context in excludedContexts checks. The key function is ResetRequestSourceImpl.processContext which handles context registration. The JIRA ticket MODCLUSTER-253 and community discussion show the root context ('/') wasn't properly excluded when 'ROOT' was in excludedContexts. The fix in 1.1.4 addressed this by correcting how empty context paths are compared against exclusion lists. This function would appear in runtime traces when processing context registration requests, and its flawed exclusion check would be triggered during exploitation attempts to access the root context.
Ongoing coverage of React2Shell