Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-11985

Опубликовано: 07 авг. 2020
Источник: redhat
CVSS3: 5.3

Описание

IP address spoofing when proxying using mod_remoteip and mod_rewrite For configurations using proxying with mod_remoteip and certain mod_rewrite rules, an attacker could spoof their IP address for logging and PHP scripts. Note this issue was fixed in Apache HTTP Server 2.4.24 but was retrospectively allocated a low severity CVE in 2020.

A flaw was found in the mod_remoteip module shipped with the httpd package. This flaw allows an attacker to spoof the IP address, resulting in the bypass of a mod_rewrite rule. The highest threat from this vulnerability is to integrity.

Отчет

This issue only affects httpd-2.4.x, therefore, httpd packages shipped with Red Hat Enterprise Linux 6 are not affected by this flaw.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5httpdNot affected
Red Hat Enterprise Linux 6httpdNot affected
Red Hat Enterprise Linux 8httpd:2.4/httpdNot affected
Red Hat JBoss Core ServiceshttpdNot affected
Red Hat JBoss Enterprise Web Server 2httpdOut of support scope
Red Hat Enterprise Linux 7httpdFixedRHBA-2015:219419.11.2015
Red Hat Software Collections for Red Hat Enterprise Linux 6httpd24-httpdFixedRHSA-2017:116126.04.2017
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUShttpd24-httpdFixedRHSA-2017:116126.04.2017
Red Hat Software Collections for Red Hat Enterprise Linux 7httpd24-httpdFixedRHSA-2017:116126.04.2017
Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUShttpd24-httpdFixedRHSA-2017:116126.04.2017

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-345
https://bugzilla.redhat.com/show_bug.cgi?id=1866559httpd: IP address spoofing when proxying using mod_remoteip and mod_rewrite

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 5 лет назад

IP address spoofing when proxying using mod_remoteip and mod_rewrite For configurations using proxying with mod_remoteip and certain mod_rewrite rules, an attacker could spoof their IP address for logging and PHP scripts. Note this issue was fixed in Apache HTTP Server 2.4.24 but was retrospectively allocated a low severity CVE in 2020.

CVSS3: 5.3
nvd
больше 5 лет назад

IP address spoofing when proxying using mod_remoteip and mod_rewrite For configurations using proxying with mod_remoteip and certain mod_rewrite rules, an attacker could spoof their IP address for logging and PHP scripts. Note this issue was fixed in Apache HTTP Server 2.4.24 but was retrospectively allocated a low severity CVE in 2020.

CVSS3: 5.3
debian
больше 5 лет назад

IP address spoofing when proxying using mod_remoteip and mod_rewrite F ...

github
больше 3 лет назад

IP address spoofing when proxying using mod_remoteip and mod_rewrite For configurations using proxying with mod_remoteip and certain mod_rewrite rules, an attacker could spoof their IP address for logging and PHP scripts. Note this issue was fixed in Apache HTTP Server 2.4.24 but was retrospectively allocated a low severity CVE in 2020.

CVSS3: 5.3
fstec
больше 9 лет назад

Уязвимость реализации модулей mod_remoteip и mod_rewrite веб-сервера Apache HTTP Server, позволяющая нарушителю осуществить подмену ip-адреса

5.3 Medium

CVSS3