Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2011-3368

Опубликовано: 05 окт. 2011
Источник: redhat
CVSS2: 2.6

Описание

The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21 does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern matches for configuration of a reverse proxy, which allows remote attackers to send requests to intranet servers via a malformed URI containing an initial @ (at sign) character.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Directory Server 8httpdWill not fix
Red Hat Enterprise Linux 4httpdFixedRHSA-2011:139220.10.2011
Red Hat Enterprise Linux 5httpdFixedRHSA-2011:139220.10.2011
Red Hat Enterprise Linux 6httpdFixedRHSA-2011:139120.10.2011
Red Hat JBoss Enterprise Web Server 1 for RHEL 5httpdFixedRHSA-2012:054207.05.2012
Red Hat JBoss Enterprise Web Server 1 for RHEL 6httpdFixedRHSA-2012:054207.05.2012
Red Hat JBoss Web Server 1.0FixedRHSA-2012:054307.05.2012

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=740045httpd: reverse web proxy vulnerability

2.6 Low

CVSS2

Связанные уязвимости

ubuntu
почти 15 лет назад

The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21 does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern matches for configuration of a reverse proxy, which allows remote attackers to send requests to intranet servers via a malformed URI containing an initial @ (at sign) character.

nvd
почти 15 лет назад

The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21 does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern matches for configuration of a reverse proxy, which allows remote attackers to send requests to intranet servers via a malformed URI containing an initial @ (at sign) character.

debian
почти 15 лет назад

The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2 ...

github
около 4 лет назад

The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21 does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern matches for configuration of a reverse proxy, which allows remote attackers to send requests to intranet servers via a malformed URI containing an initial @ (at sign) character.

oracle-oval
почти 15 лет назад

ELSA-2011-1392: httpd security and bug fix update (MODERATE)

2.6 Low

CVSS2