The mod_proxy module in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x before 2.2.18, when the Revision 1179239 patch is in place, does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern matches for configuration of a reverse proxy, which allows remote attackers to send requests to intranet servers by using the HTTP/0.9 protocol with a malformed URI containing an initial @ (at sign) character. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-3368.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apache Httpd | — | Upgrade to Apache HTTPD version 2.0.65Upgrade to Apache HTTPD version 2.2.18 | Jul 18, 2019 | Nov 30, 2011 |
| Centos_linux | — | Upgrade httpd-manualUpgrade httpdUpgrade httpd-develUpgrade httpd-toolsUpgrade mod_ssl | Dec 1, 2016 | Nov 29, 2011 |
| Debian | — | Upgrade apache2 | Jul 30, 2024 | Nov 30, 2011 |
| Hpsmh | — | Upgrade to the latest version of HP System Management Homepage | Oct 13, 2015 | Nov 29, 2011 |
| Ibm Http_server | — | Apply IBM HTTP Server version 8.0.0.2 or laterApply IBM HTTP Server Interim Fix PM48384 | Jun 22, 2018 | Nov 29, 2011 |
| Oracle_linux | — | Upgrade httpd-toolsUpgrade mod_sslUpgrade httpdUpgrade httpd-develUpgrade httpd-manual | Oct 16, 2024 | Nov 30, 2011 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Oct 26, 2011 |
| Suse | — | Upgrade apache2-example-pagesUpgrade apache2Upgrade apache2-develUpgrade apache2-workerUpgrade apache2-docUpgrade apache2-prefork | Dec 12, 2013 | Nov 29, 2011 |
| Ubuntu | — | Upgrade apache2 | Nov 19, 2024 | Nov 30, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub