{"id":"CVE-2012-1094","aliases":[],"url":"https://o3.security/vulnerability/CVE-2012-1094","summary":"JBoss AS may expose root content if excluded-contexts list is mismatched","details":"JBoss AS 7 prior to 7.1.1 and mod_cluster do not handle default hostname in the same way, which can cause the excluded-contexts list to be mismatched and the root context to be exposed.","published":"2022-04-23T00:40:48Z","modified":"2023-11-08T03:57:03.478339Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},"epss":{"score":0.01105,"percentile":0.62802,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.jboss.as:jboss-as-server","fixedVersion":"7.1.1.Final"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2012-1094"},{"type":"WEB","url":"https://access.redhat.com/security/cve/cve-2012-1094"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-1094"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2023-11-08T03:57:03.478339Z"}}