CVE-2018-11759 is an improper input-validation flaw in the Apache HTTP Server-specific component of Apache Tomcat JK Connector (mod_jk) versions 1.2.0 through 1.2.44. The connector incorrectly handled edge cases while normalizing a requested path before matching it against the URI-worker map. A specially constructed request could consequently be mapped differently than intended by the reverse-proxy configuration, exposing Tomcat application functionality that was not intended to be available through Apache HTTP Server. In affected configurations, the flaw could also bypass access controls enforced by Apache HTTP Server.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a Python-based web vulnerability scanner named Cerberus. It is designed to automate the detection of a wide range of web application vulnerabilities, including SQL injection, XSS, command injection, file inclusion, and SSRF. The tool supports both single-target and batch scanning (via file input or subdomain enumeration), and can also collect and use proxy IPs to bypass WAFs or IP bans. It features middleware fingerprinting and targeted exploitation for specific platforms (ThinkPHP, phpMyAdmin, Tomcat, Weblogic, Wordpress, Dedecms), with hardcoded exploits for known CVEs (e.g., CVE-2018-5955, CVE-2018-12613, CVE-2018-11759). The scanner can detect WAFs and attempt known bypasses, and it generates scan reports. The main entry point is 'cerberus.py', which orchestrates scanning based on command-line arguments. The codebase is modular, with core logic for payload management, proxy handling, subdomain brute-forcing, and vulnerability exploitation. Numerous endpoints are fingerprinted, including public proxy sources, file paths for LFI/RFI, and SSRF targets. The repository is operational and suitable for real-world vulnerability assessment of web applications.
This repository provides a proof-of-concept (PoC) environment for exploiting CVE-2018-11759, a path normalization vulnerability in Apache mod_jk (Tomcat JK Connector) versions 1.2.0 to 1.2.44. The vulnerability allows attackers to bypass access controls set in Apache httpd by appending a semicolon to protected endpoints (e.g., /jkstatus;), thereby gaining unauthorized access to sensitive interfaces such as the JK Status Manager. The repository includes Dockerfiles and configuration files to set up a vulnerable environment with two Tomcat clients and a load balancer running Apache httpd with mod_jk. The main exploit is demonstrated via a simple curl command that accesses the protected endpoint with a semicolon, bypassing the intended restriction. The structure consists of Docker and configuration files for both the client and load balancer, with detailed Apache and mod_jk configuration files. The PoC is operational and demonstrates the impact of the vulnerability in a controlled environment.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An information-disclosure/access-control-bypass vulnerability caused by incorrect path normalization in the Apache httpd-specific JK Connector URI-worker mapping code.
An important information-disclosure/access-control bypass in Apache Tomcat JK Connectors' httpd-specific path normalization. Crafted requests could bypass httpd access controls when only a subset of Tomcat URLs was exposed.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.