CVE-2020-11985

Source
https://nvd.nist.gov/vuln/detail/CVE-2020-11985
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-11985.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2020-11985
Aliases
Downstream
Related
Published
2020-08-07T16:15:11Z
Modified
2025-10-14T14:35:22Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N CVSS Calculator
Summary
[none]
Details

IP address spoofing when proxying using modremoteip and modrewrite For configurations using proxying with modremoteip and certain modrewrite rules, an attacker could spoof their IP address for logging and PHP scripts. Note this issue was fixed in Apache HTTP Server 2.4.24 but was retrospectively allocated a low severity CVE in 2020.

References

Affected packages

Git / github.com/apache/httpd

Affected ranges

Type
GIT
Repo
https://github.com/apache/httpd
Events