Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2020-11985

Опубликовано: 07 авг. 2020
Источник: ubuntu
Приоритет: low
EPSS Средний
CVSS2: 4.3
CVSS3: 5.3

Описание

IP address spoofing when proxying using mod_remoteip and mod_rewrite For configurations using proxying with mod_remoteip and certain mod_rewrite rules, an attacker could spoof their IP address for logging and PHP scripts. Note this issue was fixed in Apache HTTP Server 2.4.24 but was retrospectively allocated a low severity CVE in 2020.

РелизСтатусПримечание
bionic

not-affected

2.4.29-1ubuntu4.13
devel

not-affected

esm-infra-legacy/trusty

needed

esm-infra/bionic

not-affected

2.4.29-1ubuntu4.13
esm-infra/focal

not-affected

esm-infra/xenial

released

2.4.18-2ubuntu3.15
focal

not-affected

groovy

not-affected

hirsute

not-affected

impish

not-affected

Показывать по

EPSS

Процентиль: 94%
0.15318
Средний

4.3 Medium

CVSS2

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
redhat
больше 5 лет назад

IP address spoofing when proxying using mod_remoteip and mod_rewrite For configurations using proxying with mod_remoteip and certain mod_rewrite rules, an attacker could spoof their IP address for logging and PHP scripts. Note this issue was fixed in Apache HTTP Server 2.4.24 but was retrospectively allocated a low severity CVE in 2020.

CVSS3: 5.3
nvd
больше 5 лет назад

IP address spoofing when proxying using mod_remoteip and mod_rewrite For configurations using proxying with mod_remoteip and certain mod_rewrite rules, an attacker could spoof their IP address for logging and PHP scripts. Note this issue was fixed in Apache HTTP Server 2.4.24 but was retrospectively allocated a low severity CVE in 2020.

CVSS3: 5.3
debian
больше 5 лет назад

IP address spoofing when proxying using mod_remoteip and mod_rewrite F ...

github
больше 3 лет назад

IP address spoofing when proxying using mod_remoteip and mod_rewrite For configurations using proxying with mod_remoteip and certain mod_rewrite rules, an attacker could spoof their IP address for logging and PHP scripts. Note this issue was fixed in Apache HTTP Server 2.4.24 but was retrospectively allocated a low severity CVE in 2020.

CVSS3: 5.3
fstec
больше 9 лет назад

Уязвимость реализации модулей mod_remoteip и mod_rewrite веб-сервера Apache HTTP Server, позволяющая нарушителю осуществить подмену ip-адреса

EPSS

Процентиль: 94%
0.15318
Средний

4.3 Medium

CVSS2

5.3 Medium

CVSS3