← back
CVE-2020-11985CWE-345

CVE-2020-11985

3Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackepss 6.8%
exploitation probability
6.8%top 7% of all CVEs
observed exploitation
nono source reports it
In short

An attacker can fake their IP address when Apache uses certain proxy and URL rewriting modules together. This tricks logging systems and web applications into thinking the request came from a different source.

Technical detail

When mod_remoteip and mod_rewrite are configured for proxying, an attacker can manipulate request headers to spoof their source IP address. The vulnerability allows bypass of IP-based access controls and falsification of audit logs. Exploitation requires the vulnerable module configuration to be active on the target server.

Summary generated and translated by AI from the official description.
IP address spoofing when proxying using mod_remoteip and mod_rewrite For configurations using proxying with mod_remoteip and certain mod_rewrite rules, an attacker could spoof their IP address for logging and PHP scripts. Note this issue was fixed in Apache HTTP Server 2.4.24 but was retrospectively allocated a low severity CVE in 2020.
Affected products
n/a · Apache HTTP Server