Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2011-3368

Опубликовано: 05 окт. 2011
Источник: redhat
CVSS2: 2.6
EPSS Высокий

Описание

The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21 does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern matches for configuration of a reverse proxy, which allows remote attackers to send requests to intranet servers via a malformed URI containing an initial @ (at sign) character.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Certificate System 7.3httpdWill not fix
Red Hat Directory Server 8httpdWill not fix
Red Hat Enterprise Linux 4httpdFixedRHSA-2011:139220.10.2011
Red Hat Enterprise Linux 5httpdFixedRHSA-2011:139220.10.2011
Red Hat Enterprise Linux 6httpdFixedRHSA-2011:139120.10.2011
Red Hat JBoss Enterprise Web Server 1 for RHEL 5httpdFixedRHSA-2012:054207.05.2012
Red Hat JBoss Enterprise Web Server 1 for RHEL 6httpdFixedRHSA-2012:054207.05.2012
Red Hat JBoss Web Server 1.0FixedRHSA-2012:054307.05.2012

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=740045httpd: reverse web proxy vulnerability

EPSS

Процентиль: 99%
0.79132
Высокий

2.6 Low

CVSS2

Связанные уязвимости

ubuntu
почти 14 лет назад

The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21 does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern matches for configuration of a reverse proxy, which allows remote attackers to send requests to intranet servers via a malformed URI containing an initial @ (at sign) character.

nvd
почти 14 лет назад

The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21 does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern matches for configuration of a reverse proxy, which allows remote attackers to send requests to intranet servers via a malformed URI containing an initial @ (at sign) character.

debian
почти 14 лет назад

The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2 ...

github
больше 3 лет назад

The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21 does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern matches for configuration of a reverse proxy, which allows remote attackers to send requests to intranet servers via a malformed URI containing an initial @ (at sign) character.

oracle-oval
почти 14 лет назад

ELSA-2011-1392: httpd security and bug fix update (MODERATE)

EPSS

Процентиль: 99%
0.79132
Высокий

2.6 Low

CVSS2