← Back to list

Tomcat AJP vulnerability and Razuna

Nitai · 2020-03-06 23:41 · 0 claps · 0.6 min read
#digital-asset-management #open-source #razuna
Open on Medium ↗
Wiki topics: BIZ · Business Strategy 🔒 · Cybersecurity 🔓 · Open Source

Tomcat AJP vulnerability and Razuna

We got notified that there is an AJP security vulnerability with all Apache Tomcat releases. The issue is discussed as CVE-2929–1938. A remote, unauthenticated/untrusted attacker could exploit this AJP configuration to read web application files from a server exposing the AJP port to untrusted clients.

That said, the default Tomcat instance that is included in our Razuna download has the AJP connector disabled by default. Also, all customers of our dedicated Razuna servers, are already protected!

However, if you installed Razuna on your customer Tomcat installation, please make sure to disable the AJP connector in the server.xml file that can be found in the tomcat/config folder.

Originally published at Helpmonks Blog.


메타데이터
post_id
e55db1da910d
slug
tomcat-ajp-vulnerability-and-razuna-e55db1da910d
url
https://medium.com/@nitai/tomcat-ajp-vulnerability-and-razuna-e55db1da910d
canonical_url
https://medium.com/@nitai/tomcat-ajp-vulnerability-and-razuna-e55db1da910d
author_url
https://medium.com/@nitai
status
ok
fetched_at
2026-07-29 06:11:15