Описание
IP address spoofing when proxying using mod_remoteip and mod_rewrite For configurations using proxying with mod_remoteip and certain mod_rewrite rules, an attacker could spoof their IP address for logging and PHP scripts. Note this issue was fixed in Apache HTTP Server 2.4.24 but was retrospectively allocated a low severity CVE in 2020.
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | not-affected | 2.4.29-1ubuntu4.13 |
| devel | not-affected | |
| esm-infra-legacy/trusty | needed | |
| esm-infra/bionic | not-affected | 2.4.29-1ubuntu4.13 |
| esm-infra/focal | not-affected | |
| esm-infra/xenial | released | 2.4.18-2ubuntu3.15 |
| focal | not-affected | |
| groovy | not-affected | |
| hirsute | not-affected | |
| impish | not-affected |
Показывать по
EPSS
4.3 Medium
CVSS2
5.3 Medium
CVSS3
Связанные уязвимости
IP address spoofing when proxying using mod_remoteip and mod_rewrite For configurations using proxying with mod_remoteip and certain mod_rewrite rules, an attacker could spoof their IP address for logging and PHP scripts. Note this issue was fixed in Apache HTTP Server 2.4.24 but was retrospectively allocated a low severity CVE in 2020.
IP address spoofing when proxying using mod_remoteip and mod_rewrite For configurations using proxying with mod_remoteip and certain mod_rewrite rules, an attacker could spoof their IP address for logging and PHP scripts. Note this issue was fixed in Apache HTTP Server 2.4.24 but was retrospectively allocated a low severity CVE in 2020.
IP address spoofing when proxying using mod_remoteip and mod_rewrite F ...
IP address spoofing when proxying using mod_remoteip and mod_rewrite For configurations using proxying with mod_remoteip and certain mod_rewrite rules, an attacker could spoof their IP address for logging and PHP scripts. Note this issue was fixed in Apache HTTP Server 2.4.24 but was retrospectively allocated a low severity CVE in 2020.
Уязвимость реализации модулей mod_remoteip и mod_rewrite веб-сервера Apache HTTP Server, позволяющая нарушителю осуществить подмену ip-адреса
EPSS
4.3 Medium
CVSS2
5.3 Medium
CVSS3