CVE-2020-11985
07.08.2020, 16:15
IP address spoofing when proxying using mod_remoteip and mod_rewrite For configurations using proxying with mod_remoteip and certain mod_rewrite rules, an attacker could spoof their IP address for logging and PHP scripts. Note this issue was fixed in Apache HTTP Server 2.4.24 but was retrospectively allocated a low severity CVE in 2020.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| apache | http_server | 2.4.1 ≤ 𝑥 ≤ 2.4.23 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache2 |
| ||||||||||||||||
| apache2-doc |
| ||||||||||||||||
| apache2-example-pages |
| ||||||||||||||||
| apache2-prefork |
| ||||||||||||||||
| apache2-utils |
| ||||||||||||||||
| apache2-worker |
|
Red Hat Enterprise Linux Releases
Common Weakness Enumeration
References