CVE-2020-11985
Vulnerability Summary
Timeline
Description
IP address spoofing when proxying using mod_remoteip and mod_rewrite For configurations using proxying with mod_remoteip and certain mod_rewrite rules, an attacker could spoof their IP address for logging and PHP scripts. Note this issue was fixed in Apache HTTP Server 2.4.24 but was retrospectively allocated a low severity CVE in 2020.
CVSS Metrics
- v3.1•MEDIUM•Score: 5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- v2.0•MEDIUM•Score: 4.3AV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS Trends
Current EPSS score: 6.81%• Percentile: 94%
Techniques & Countermeasures
- CWE-345•Insufficient Verification of Data Authenticity
The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
Affected Systems
- apache•http_server
≥ 2.4.1, ≤ 2.4.23
- debian•apache2
< 2.4.25-1 | < 2.4.25-1 | < 2.4.25-1 | < 2.4.25-1
- ubuntu•apache2
all | < 2.4.18-2ubuntu3.15
- redhat•httpd
< 0:2.4.6-40.el7 | < 0:2.4.6-40.el7 | < 0:2.4.6-40.el7 | < 0:2.4.6-40.el7
- redhat•httpd-debuginfo
< 0:2.4.6-40.el7 | < 0:2.4.6-40.el7 | < 0:2.4.6-40.el7 | < 0:2.4.6-40.el7
- redhat•httpd-devel
< 0:2.4.6-40.el7 | < 0:2.4.6-40.el7 | < 0:2.4.6-40.el7 | < 0:2.4.6-40.el7
- redhat•httpd-manual
< 0:2.4.6-40.el7 | < 0:2.4.6-40.el7 | < 0:2.4.6-40.el7 | < 0:2.4.6-40.el7
- redhat•httpd-tools
< 0:2.4.6-40.el7 | < 0:2.4.6-40.el7 | < 0:2.4.6-40.el7 | < 0:2.4.6-40.el7
- redhat•mod_ldap
< 0:2.4.6-40.el7 | < 0:2.4.6-40.el7 | < 0:2.4.6-40.el7 | < 0:2.4.6-40.el7
- redhat•mod_proxy_html
< 1:2.4.6-40.el7 | < 1:2.4.6-40.el7 | < 1:2.4.6-40.el7 | < 1:2.4.6-40.el7
- redhat•mod_session
< 0:2.4.6-40.el7 | < 0:2.4.6-40.el7 | < 0:2.4.6-40.el7 | < 0:2.4.6-40.el7
- redhat•mod_ssl
< 1:2.4.6-40.el7 | < 1:2.4.6-40.el7 | < 1:2.4.6-40.el7 | < 1:2.4.6-40.el7
References (55)
- https://httpd.apache.org/security/vulnerabilities_24.html
- https://security.gentoo.org/glsa/202008-04
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HYVYE2ZERFXDV6RMKK3I5SDSDQLPSEIQ/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/A2RN46PRBJE7E7OPD4YZX5SVWV5QKGV5/
- https://www.oracle.com/security-alerts/cpujan2021.html
- https://security.netapp.com/advisory/ntap-20200827-0002/
- https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E
- https://lists.apache.org/thread.html/r09bb998baee74a2c316446bd1a41ae7f8d7049d09d9ff991471e8775%40%3Ccvs.httpd.apache.org%3E
- https://lists.apache.org/thread.html/rc998b18880df98bafaade071346690c2bc1444adaa1a1ea464b93f0a%40%3Ccvs.httpd.apache.org%3E
- https://lists.apache.org/thread.html/r03ee478b3dda3e381fd6189366fa7af97c980d2f602846eef935277d%40%3Ccvs.httpd.apache.org%3E
- https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E
- https://lists.apache.org/thread.html/r3c5c3104813c1c5508b55564b66546933079250a46ce50eee90b2e36%40%3Ccvs.httpd.apache.org%3E
- https://lists.apache.org/thread.html/rcc44594d4d6579b90deccd4536b5d31f099ef563df39b094be286b9e%40%3Ccvs.httpd.apache.org%3E
- https://lists.apache.org/thread.html/rd336919f655b7ff309385e34a143e41c503e133da80414485b3abcc9%40%3Ccvs.httpd.apache.org%3E
- https://lists.apache.org/thread.html/r476d175be0aaf4a17680ef98c5153b4d336eaef76fb2224cc94c463a%40%3Ccvs.httpd.apache.org%3E
- https://lists.apache.org/thread.html/r76142b8c5119df2178be7c2dba88fde552eedeec37ea993dfce68d1d%40%3Ccvs.httpd.apache.org%3E
- https://access.redhat.com/errata/RHBA-2015:2194
- https://bugzilla.redhat.com/show_bug.cgi?id=1125276
- https://bugzilla.redhat.com/show_bug.cgi?id=1160625
- https://bugzilla.redhat.com/show_bug.cgi?id=1162159
- https://bugzilla.redhat.com/show_bug.cgi?id=1169081
- https://bugzilla.redhat.com/show_bug.cgi?id=1170206
- https://bugzilla.redhat.com/show_bug.cgi?id=1170214
- https://bugzilla.redhat.com/show_bug.cgi?id=1170215
- https://bugzilla.redhat.com/show_bug.cgi?id=1170220
- https://bugzilla.redhat.com/show_bug.cgi?id=1176449
- https://bugzilla.redhat.com/show_bug.cgi?id=1179306
- https://bugzilla.redhat.com/show_bug.cgi?id=1180745
- https://bugzilla.redhat.com/show_bug.cgi?id=1184118
- https://bugzilla.redhat.com/show_bug.cgi?id=1188779
- https://bugzilla.redhat.com/show_bug.cgi?id=1210091
- https://bugzilla.redhat.com/show_bug.cgi?id=1214398
- https://bugzilla.redhat.com/show_bug.cgi?id=1214401
- https://bugzilla.redhat.com/show_bug.cgi?id=1214430
- https://bugzilla.redhat.com/show_bug.cgi?id=1221575
- https://bugzilla.redhat.com/show_bug.cgi?id=1222328
- https://bugzilla.redhat.com/show_bug.cgi?id=1225820
- https://bugzilla.redhat.com/show_bug.cgi?id=1226015
- https://bugzilla.redhat.com/show_bug.cgi?id=1227219
- https://bugzilla.redhat.com/show_bug.cgi?id=1231924
- https://bugzilla.redhat.com/show_bug.cgi?id=1235383
- https://bugzilla.redhat.com/show_bug.cgi?id=1239164
- https://bugzilla.redhat.com/show_bug.cgi?id=1242416
- https://bugzilla.redhat.com/show_bug.cgi?id=1242503
- https://bugzilla.redhat.com/show_bug.cgi?id=1255480
- https://bugzilla.redhat.com/show_bug.cgi?id=1263975
- https://security.access.redhat.com/data/csaf/v2/advisories/2015/rhba-2015_2194.json
- https://access.redhat.com/security/cve/CVE-2020-11985
- https://bugzilla.redhat.com/show_bug.cgi?id=1866559
- https://www.cve.org/CVERecord?id=CVE-2020-11985
- https://nvd.nist.gov/vuln/detail/CVE-2020-11985
- https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2020-11985
- https://ubuntu.com/security/CVE-2020-11985
- https://www.openwall.com/lists/oss-security/2020/08/07/2
- https://security-tracker.debian.org/tracker/CVE-2020-11985