cve-2018-11759. php, in which an attacker can trigger a call to the exec method with (for example) OS commands in the opt parameter. cve-2018-11759

 
php, in which an attacker can trigger a call to the exec method with (for example) OS commands in the opt parametercve-2018-11759  Failed exploit attempts will likely result in denial of service conditions

1. Detail. 2018-10-31: not yet calculated: CVE-2018-11759 MISC: N/A -- N/A:. # at the same time, having more than 8 also crashes lld for firefox buildsystems (why?). uWSGI PHP目录穿越漏洞(CVE-2018-7490) 文件上传: poc-10127: PowerCreator CMS 文件上传getshell: 命令执行: poc-10126: Dlink 路由器 远程命令执行 (CVE-2019-16920) 目录穿越: poc-10125: Tomcat mod_jk访问控制绕过漏洞(CVE-2018-11759) 命令执行: poc-10124: Nexus Repository Manager 3. 4反序列化漏洞 CVE-2016-4437{"payload":{"allShortcutsEnabled":false,"fileTree":{"pocs":{"items":[{"name":"74cms-sqli-1. Modified. 0 to 8. Note: NVD Analysts have published a CVSS score for this CVE based on publicly available information at the time of analysis. 44 did not handle some edge cases correctly. 2, and Firefox ESR < 68. 官方修复针对. The mission of the CVE® Program is to identify, define, and catalog publicly disclosed cybersecurity vulnerabilities. 4, 12. ORG and CVE Record Format JSON are underway. 3 prior to 4. CVE-2018-11759 Learn more at National Vulnerability Database (NVD) • CVSS Severity Rating • Fix Information • Vulnerable Software Versions • SCAP Mappings • CPE Information Description Vulnerability Details : CVE-2018-11759. zlib before 1. Red Hat Insights Increase visibility into IT operations to detect and resolve technical issues before they impact your business. Modified. Plan and track work. This vulnerability has been modified since it was last analyzed by the NVD. 2, and Firefox ESR < 68. TerraMaster TOS before 4. - download-latest-epss-scores. Description This update for apache2-mod_jk fixes the following issues : Security issues fixed : CVE-2018-11759: Fixed connector path traversal due to mishandled HTTP requests in (bsc#1114612). It is awaiting reanalysis which may result in further changes to the information provided. Attack chain overview. {"payload":{"allShortcutsEnabled":false,"fileTree":{"pocs":{"items":[{"name":"74cms-sqli-1. 尽管此问题与CVE-2018-1323之间存在某些重叠之处,但它们并不完全相同。 POC 以下概念验证显示了如何利用CVE-2018-11759及其对目标信息系统的影响。 环境设定 docker-compose up -d 请耐心等待,第一次的过程可能会很长。 镜像新增日志 . 2. Note: NVD Analysts have published a CVSS score for this CVE based on publicly available information at the time of analysis. CVE-2017-12615. Contribute to 0nk4r/templates development by creating an account on GitHub. 2. 3. yml","contentType":"file"},{"name":"74cms. Note: NVD Analysts have published a CVSS score for this CVE based on publicly available information at the time of analysis. 5 and versions 4. {"payload":{"allShortcutsEnabled":false,"fileTree":{"pocs":{"items":[{"name":"74cms-sqli-1. yml","contentType":"file"},{"name":"74cms. 3 prior to 4. An update that solves one vulnerability can now be installed. Proprietary Code CVEs: Description: CVSS Base Score: CVSS Vector String: CVE-2021-21589: Dell Unity, Unity XT, and UnityVSA versions before 5. 输入文件批量扫描. 51. 6. 0. Name Description; CVE-2018-11759: The Apache Web Server (specific code that normalised the requested path before matching it to the URI-worker map in Apache Tomcat JK (mod_jk) Connector 1. • CVSS Severity Rating • Fix Information • Vulnerable Software Versions • SCAP Mappings • CPE Information. Because of integer overflows in CompositeDeepScanLine::Data::handleDeepFrameBuffer and readSampleCountForLineBlock, an attacker can write to an out-of-bounds pointer. x prior to 1. openwall. CVE Additional Information This product uses data from the NVD API but is not endorsed or certified by the NVD. . Apache NiFi Api 远程代码执行 RCE. The mission of the CVE® Program is to identify, define, and catalog publicly disclosed cybersecurity vulnerabilities. • CVSS Severity Rating • Fix Information • Vulnerable Software Versions • SCAP Mappings • CPE Information. authenticate. 漏洞原因是由于没有过滤Http包头的特定字段,导致可以构造访问系统文件的路径,从而导致可访问任意文件,攻击者可以利用该漏洞读取设备的任意文件,这将严重威胁采用Mini_ . myscan是参考awvs的poc目录架构,pocsuite3、sqlmap等代码框架,以及搜集互联网上大量的poc,由python3开发而成的被动扫描工具。 CVE-2018-11759. A Docker environment is available to test this vulnerability on our GitHub. 44 did not handle some edge cases correctly. 2. Our aim is to serve the most comprehensive collection of exploits gathered through direct submissions, mailing lists, as well as other public sources, and present them. 2. 2. The proof of concept below shows how to exploit the CVE-2018-11759 as well as its impact on the information system. 8 HIGH. x prior to 5. 0 U1c, 6. This CVE is in CISA's Known Exploited Vulnerabilities Catalog Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements. CVE-2018-17179 NVD Published Date: 05/17/2019 NVD Last Modified: 05/20/2019 Source: MITRE. 2. Because of integer overflows in CompositeDeepScanLine::Data::handleDeepFrameBuffer and readSampleCountForLineBlock, an attacker can write to an out-of-bounds pointer. CVSS 7. A malicious user (or attacker) can craft a message to the broker that can lead to a. 9. 5 。Like the one assigned CVE-2018-1323, this vulnerability (CVE-2018-11759) exists because Apache Tomcat Web Server (HTTPD)’s code which is used to normalize the requested path fails to properly handle edge cases (for example, filtering out the semicolon (;)) before mapping it to the URI-work map in Apache Tomcat JK (mod_jk) Connector. CVE-2018-11770 Detail Description . The Apache Web Server (specific code that normalised the requested path before matching it to the URI-worker map did not handle some edge cases correctly. Note: NVD Analysts have published a CVSS score for this CVE based on publicly available information at the time of analysis. 0. The archive main are a script in bash for exploiting. 0至7. 文件路径需为绝对路径. 1. Home > CVE > CVE-2018-13379  CVE-ID; CVE-2018-13379: Learn more at National Vulnerability Database (NVD) • CVSS Severity Rating • Fix Information • Vulnerable Software Versions • SCAP. 4. Description; In FreeBSD before 11. 2. 44 did not handle some edge cases correctly. e. It is possible to read the advisory at openwall. S. CVE-2018-11759 at MITRE. 0. replies . e-books, white papers, videos & briefsDate: Wed, 31 Oct 2018 18:21:48 +0000 From: Mark Thomas <[email protected] to 1. {"payload":{"allShortcutsEnabled":false,"fileTree":{"":{"items":[{"name":"1Panel loadfile 后台文件读取漏洞. CVE-2018-25032 Detail Modified. (rjung) * Security: CVE-2018-11759 Connector path traversal [bsc#1114612] Update to version 1. Spring Framework, versions 5. 1. 5 and 12. 0. 45 Fixes: * Correct regression in 1. 2. If only a sub-set of the URLs supported by Tomcat were exposed via. The CNA has not provided a score within the CVE. 2. 8. py -file absolute path. This vulnerability affects Firefox < 70, Thunderbird < 68. 需为txt文本格式,确保每一行只有一个域名. 0 to 1. Transition to the all-new CVE website at. Manage code changes Issues. An issue was discovered in OpenEXR before 2. 2. 0, 12. CVE-2018-11759. CVE-2018-11759 at MITRE. If only a sub-set of the URLs supported by Tomcat were exposed via then it was. 2021-11-05 ; vulfocus/youphptube-cve_2019_5120 ; vulfocus/youphptube-cve_2019_18662 ; vulfocus/wuzhicms-cve_2018_11528 ; vulfocus. com. yml","path":"pocs/74cms-sqli-1. It is awaiting reanalysis which may result in further changes to the information provided. TOTAL CVE Records: 217649. resources library. 1. 44 access. 2. View Cart Exit SUSE Federal > Shop Careers. OpenCVE; Vulnerabilities (CVE) CVE-2020-11759; A n issue was discovered in OpenEXR before 2. 1. Vulnerability summary. BZ - 1605048 - CVE-2018-1333 mod_Too much time allocated to workers, possibly leading to DoS BZ - 1633399 - CVE-2018-11763 DoS for HTTP/2. gitignore","path. yml","contentType":"file"},{"name. 751 lines20 KiBPlaintextRaw Permalink Blame History. 18, and older unsupported versions) allow web applications to change the HTTP request method to any HTTP method (including TRACE) using the HiddenHttpMethodFilter in Spring MVC. 0. 1. This vulnerability affects Firefox < 70, Thunderbird < 68. • CVSS Severity Rating • Fix Information • Vulnerable Software Versions • SCAP Mappings • CPE Information. Automate any workflow Packages. Vulnerability Name Date Added Due Date Required Action; ThinkPHP Remote Code Execution Vulnerability: 11/03/2021: 05/03/2022. Multiple issues - session and cookies manipulation, internals IP disclosure. Home > CVE > CVE-2018-11777. Modified. An issue was discovered in OpenEXR before 2. 3. Implement Identificador-CVE-2018-11759 with how-to, Q&A, fixes, code snippets. 44 Description: The Apache Web Server (specific code that normalised the requested path before matching it to the URI-worker map did not handle. Go to for: CVSS Scores. AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. 4反序列化漏洞 CVE-2016-4437; Apache SkyWalking graphql SQL注入漏洞 CVE-2020-9483; Apache Solr JMX服务 RCE CVE-2019-12409 Apache Mod_jk 访问控制权限绕过 CVE-2018-11759; Apache NiFi Api 远程代码执行 RCE; Apache OF Biz RMI Bypass RCE CVE 2021 29200; Apache OFBiz RMI反序列化漏洞 CVE-2021-26295; Apache ShenYu dashboardUser 账号密码泄漏漏洞 CVE-2021-37580; Apache Shiro 1. The mission of the CVE® Program is to identify, define, and catalog publicly disclosed cybersecurity vulnerabilities. Spring Framework, versions 5. zlib before 1. 2, and Firefox ESR < 68. This affects VMware vCenter Server (7. 4. CVE-2018-11759. 0. 2. 3, when a message with COTP message length field with value < 4 is received an integer underflow will happen leading to heap buffer overflow. This vulnerability is known as CVE-2017-15715 since 10/21/2017. Host and manage packages Security. Format String vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges on an affected device. cve-2018-7602_poc. /Content/img&idx=6. CVE Dictionary Entry: CVE-2018-11771 NVD Published Date: 08/16/2018 NVD Last Modified: 11/06/2023 Source: Apache Software. ORG CVE Record Format JSON Legacy CVE List download formats will be phased out beginning January 1, 2024 New CVE List download format is. August 24, 2018. Go to for: CVSS Scores. Modified. Find and fix vulnerabilities Codespaces. 2. CVE-2018-11759: Fixed connector path traversal due to mishandled HTTP requests in (bsc#1114612). A flaw was found in RPC request using gfs3_rename_req in glusterfs server. A spear-phishing email purporting to be from the Ministry of Foreign Affairs (MFA) of the Islamic Republic of Afghanistan was sent to very specific targets and asked for “resources, telecommunication services and satellite maps”. 1, 12. Description This update for apache2-mod_jk fixes the following issue : Security issue fixed : CVE-2018-11759: Fixed connector path traversal due to mishandled HTTP requests in (bsc#1114612). yml","path":"pocs/74cms-sqli-1. {"payload":{"allShortcutsEnabled":false,"fileTree":{"pocs":{"items":[{"name":"74cms-sqli-1. 2. New CVE List download format is available now. In Apache Commons Beanutils 1. yml","path":"pocs/74cms-sqli-1. CVE-2018-7490 Detail Description . md","path":"(CVE-2016-8869. sh CVE-2018-11759. 6. shCVE-2018-11759. Remote attackers may use a specially crafted request with directory-traversal sequences ('. More information: Raphael Arrouas and Jean Lejeune discovered an access control bypass vulnerability in mod_jk, the Apache connector for the Tomcat Java servlet engine. 161. Thinkphp CVE-2018-5955. This CVE is in CISA's Known Exploited Vulnerabilities Catalog Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements. This vulnerability has been modified since it was last analyzed by the NVD. com If only a sub-set of the URLs supported by Tomcat were exposed via then it was possible for a specially constructed request to expose application functionality through the reverse proxy that was not intended for clients accessing the application via the reverse proxy. 0 remote code execution vulnerability in the Big-IP administrative interface. NOTICE: Legacy CVE. The mission of the CVE® Program is to identify, define, and catalog publicly disclosed cybersecurity vulnerabilities. 2. 2. yml","contentType":"file"},{"name":"74cms. ORG and CVE Record Format JSON are underway. CVE-2018-15719. apache. (rjung) * Improve path parameter parsing so that the session ID specified by the session_path worker property for load-balanced workers can be extracted from. We also display any CVSS information provided within the CVE List from the CNA. 45 Fixes: * Correct regression in 1. The Apache Software Foundation accordingly issued a security advisory ( S2-057) that provides. 4. 46 Apache Tomcat版本7. | Follow CVE. Due to discrepancies between the specifications of and Tomcat for path resolution, Apache mod_jk Connector 1. 1 data. TOTAL CVE Records: Transition to the all-new CVE website at Legacy CVE List download formats will be New CVE List download format is. yaml at master · bugbountydude/Nuclei-TamplatesBackupDescription. 2. Question: Explain what happened in this cases in details and how it can be fixed Important: Information disclosure CVE-2018-11759 The Apache Web Server (specific code. Home > CVE > CVE-2018-11659  CVE-ID; CVE-2018-11659: Learn more at National Vulnerability Database (NVD) • CVSS Severity Rating • Fix Information • Vulnerable Software Versions • SCAP. Home > CVE > CVE-2018-5159  CVE-ID; CVE-2018-5159: Learn more at National Vulnerability Database (NVD) • CVSS Severity Rating • Fix Information • Vulnerable Software Versions • SCAP. yml","path":"pocs/74cms-sqli-1. Account. 0. 尽管此问题与CVE-2018-1323之间存在某些重叠之处,但它们并不完全相同。 POC 以下概念验证显示了如何利用CVE-2018-11759及其对目标信息系统的影响。 环境设定 docker-compose up -d 请耐心等待,第一次的过程可能会很长。 CVE-2018-11759 : docker pull vulfocus/apache-CVE-2018-11759 : CVE-2018-11759 : Vulfocus : CVE-2020-13925 : docker pull vulfocus/kylin-cve_2020_13925 : uWSGI PHP目录穿越漏洞(CVE-2018-7490) 文件上传: poc-10127: PowerCreator CMS 文件上传getshell: 命令执行: poc-10126: Dlink 路由器 远程命令执行 (CVE-2019-16920) 目录穿越: poc-10125: Tomcat mod_jk访问控制绕过漏洞(CVE-2018-11759) 命令执行: poc-10124: Nexus Repository Manager 3. 2. 5. md","path":"Web. 1. e-books, white papers, videos & briefsThe mission of the CVE® Program is to identify, define, and catalog publicly disclosed cybersecurity vulnerabilities. 0. 44 that broke request handling for OPTIONS * requests. The weakness was shared 03/26/2018 (oss-sec). Saved searches Use saved searches to filter your results more quickly(rjung) * Security: CVE-2018-11759 Connector path traversal [bsc#1114612] Update to version 1. 1. yml","path":"pocs/74cms-sqli-1. CVE-ID; CVE-2018-11759: Learn more at National Vulnerability Database (NVD). 9, and older unsupported versions allow applications to serve arbitrary configuration files through the spring-cloud-config-server module. 0 身份认证绕过漏洞 CVE-2020-13933Figure 1. 需为txt文本格式,确保每一行只有一个域名. Contribute to xinZa1/template development by creating an account on GitHub. SECTRACK:1040627. 0. The archive main are a script in bash for exploiting. 1, and includes bug fixes, enhancements,. 11 (in 4. Description. An attacker could have caused 4 bytes of HMAC output to be written past the end of a buffer stored on the stack. 0 Oracle WebLogic Server 12. CVE-2017-11610 Detail. 2. TOTAL CVE Records: 215899 NOTICE: Transition to the all-new CVE website at WWW. yml","contentType":"file"},{"name":"74cms. yml","contentType":"file"},{"name. 5. 【CVE-2018-11759】Apache mod_jk访问控制的绕过漏洞复现,灰信网,软件开发博客聚合,程序员专属的优秀博客文章阅读平台。Apache Mod_jk 访问控制权限绕过 CVE-2018-11759; Apache NiFi Api 远程代码执行 RCE; Apache OF Biz RMI Bypass RCE CVE 2021 29200; Apache OFBiz RMI反序列化漏洞 CVE-2021-26295; Apache ShenYu dashboardUser 账号密码泄漏漏洞 CVE-2021-37580; Apache Shiro 小于1. {"payload":{"allShortcutsEnabled":false,"fileTree":{"docs-base/docs/webserver":{"items":[{"name":"images","path":"docs-base/docs/webserver/images","contentType. NOTICE: Legacy CVE. Verificación de vulnerabilidad 0x04. BaseURL}}' variables: - endpoint: | jkstatus jkstatus; requests. This vulnerability has been modified since it was last analyzed by the NVD. 0 to 1. Description The Apache Web Server (specific code that normalised the requested path before matching it to the URI-worker map in Apache Tomcat JK (mod_jk) Connector 1. Red Hat has been made aware of a command injection flaw found in a script included in the DHCP client (dhclient) packages in Red Hat Enterprise Linux 6 and 7. The CVSS Calculator can be used Freely via our vDNA API. > CVE-2018-15473. Note: NVD Analysts have published a CVSS score for this CVE based on publicly available information at the time of analysis. 1. {"payload":{"allShortcutsEnabled":false,"fileTree":{"pocs":{"items":[{"name":"74cms-sqli-1. 2. 06/09/2018 : First contact with Apache Tomcat security team; 06/09/2018 : First response from Apache Tomcat security team; 13/10/2018 : mod_jk v1. 23 to 7. CVE info copied to clipboard. A Docker environment is available to test this vulnerability on our GitHub. About CVE CVE & NVD Relationship Documentation & Guidance. CVE-2020-11759 2020-04-28T17:39:52 Description. Weakness. /examples/ - Apache Tomcat examples are available for public. CVSS v3. 3. The Apache Web Server (specific code that normalised the requested path before matching it to the URI-worker map in Apache Tomcat JK (mod_jk) Connector. 2, versions 2. Proposed (Legacy) N/A. For More Information: (select "Other" from dropdown) The mission of the CVE® Program is to identify, define, and catalog publicly disclosed cybersecurity vulnerabilities. Awesome CVE POC is a curated list of proof-of-concept exploits for various common vulnerabilities affecting different software and systems. yml","path":"pocs/74cms-sqli-1. The Apache Web Server (specific code that normalised the requested path before matching it to the URI-worker map in Apache Tomcat JK (mod_jk) Connector 1. CVE-2018-10759 NVD Published Date: 05/16/2018 NVD Last Modified: 05/06/2020 Source: MITRE. It is comprised of the Apache Tomcat Servlet container, JBoss HTTP Connector (mod_cluster), the PicketLink Vault extension for Apache Tomcat, and the Tomcat Native library. Note: NVD Analysts have published a CVSS score for this CVE based on publicly available information at the time of analysis. 2. 1. NOTE: this product is unrelated to Ignite Realtime Spark. CPEs for CVE-2018-11759 . 15. Spring Framework (versions 5. py -target -midlleware weblogic. 44 did not handle some edge cases correctly. 44 did not handle some edge cases correctly. The Apache Web Server (specific code that normalised the requested path before matching it to the URI-worker map did not handle some edge cases correctly. Helpid: CVE-2018-11759 info: name: Apache Tomcat JK Status Manager Exposed risk: High params: - root: '{{. 6, and older unsupported versions allow applications to serve arbitrary configuration files through the spring-cloud-config-server module. An issue was discovered in OpenEXR before 2. Detail. Skip to content Toggle navigation. I gathered these nuclei templates from several github repositories. DoS (CVE-2018-1333) mod_jk: connector path traversal due to mishandled HTTP requests in (CVE-2018-11759) ngNull pointer dereference when too large ALTSVC frame is received (CVE-2018-1000168) openssl: Handling of crafted recursive ASN. 漏洞原因是由于没有过滤Http包头的特定字段,导致可以构造访问系统文件的路径,从而导致可访问任意文件,攻击者可以利用该漏洞读取设备的任意文件,这将严重威胁采用Mini_. This exploit for CVE 2018-11759, vulnerability in apache mod_jk, module for load-balancer. Download and decompress the latest EPSS scores from the Cyentia Institute and save them in CSV, JSON, and JSONL format. Important: Information disclosure CVE-2018-11759. br","contentType":"file. Hi, In your blog post, as well as this PoC, you indicate that JkMount directives are vulnerable to this &quot;;&quot; attack. { "document": { "aggregate_severity": { "namespace": ""text": "important" }, "category": "csaf_vex. Bugs. CVE-2020-11759 2020-04-14T23:15:00 Description. Red Tools 渗透测试. The CNA has not provided a score within the CVE. The CNA has not provided a score within the CVE. CVE-2018-11759. Vulnerability Summary. 2, a remote attacker can read unintended static files via various representations of absolute or relative pathnames, as demonstrated by file: URLs and directory traversal sequences. Identificador-CVE-2018-11759 - É um simples identificador de vulnerabilidade de balanceador Mod_jk do apache, verifica três possíveis resultados de vulnerabilidade . 2. 0. {"payload":{"allShortcutsEnabled":false,"fileTree":{"Web服务器漏洞":{"items":[{"name":"images","path":"Web服务器漏洞/images","contentType":"directory. ACME Mini_任意文件读取漏洞 CVE-2018-18778 漏洞描述 . This vulnerability (CVE-2018-11759) is similar to CVE-2018-1323 in that the Apache Tomcat web server (is used to specify the code for the request path, matching the URI-Worker mapping in the Apache Tomcat JK (mod_jk) connector. Timeline. , when compressing) if the input has many distant matches. CVE-2018-11759 at MITRE. CVE-2019-11759 Common Vulnerabilities and Exposures. 2. x before 7. 2. 0 onward, Apache Spark's standalone master exposes a REST API for job submission, in addition to the submission mechanism used by spark-submit. 1. CVE-2020-1102. Please navigate to for detailed documentation to build new and your own custom templates, we have also added many example templates for easy understanding. 2. 44 did not handle some edge cases correctly. 4. 4. 44 that broke request handling for OPTIONS * requests. 36 (KHTML, like. 2. 2. 0. A flaw was found in the way signature calculation was handled by cephx authentication protocol. This CVE ID is unique from CVE-2018-8249. Note: NVD Analysts have published a CVSS score for this CVE based. 2. Find and fix vulnerabilities Codespaces. Check if your instances are expose the CVE 2018-11759 . 5. Host and manage packages Security. 如果仅通过. This vulnerability occurs due to a dangling pointer in the Primetime SDK related to media player handling of listener objects. Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". 5 EPSS 97. Vulnerabilities (CVE) Vendors & Products (CPE) Categories (CWE) CVE-2020-11759. Previously, some edge cases (such as filtering “;”) were not handled correctly. 4. We also display any CVSS information provided within the CVE List from the CNA. 7. > CVE-2019-0221. 1. 07] Apache HTTP Server 2. NVD Analysts use publicly available information to associate vector strings and CVSS scores. We also display any CVSS information provided within the CVE List from the CNA. (2) [IMS-SiteMinder : 12. Please read the. yml","contentType":"file"},{"name":"74cms. If your application is used in. HIGH. 5. For more information, you can read this. Startseite Erkunden Hilfe. 本 poc 是检测什么漏洞的 Apache Tomcat JK (mod_jk) Connector path traversal(CVE-2018-11759) 测试环境 Dockerfile:. yml","path":"pocs/74cms-sqli-1. 12 allows memory corruption when deflating (i. 0 to 1. CVE. Explain what happened in this cases in details and how it can be fixed . Timeline. CVE-2018-11759 Apache Tomcat JK (mod_jk) Connector path traversal Severity: Important Vendor: The Apache Software Foundation Versions Affected: - Apache Tomcat JK mod_jk Connector 1. 0. 2. {"payload":{"allShortcutsEnabled":false,"fileTree":{"":{"items":[{"name":"Nuclei-Templates","path":"Nuclei-Templates","contentType":"directory"},{"name":"foulenzer.