← back
CVE-2020-11985

CVE-2020-11985

EPSS 5.9%CWE-345
In short

An attacker can fake their IP address when Apache uses certain proxy and URL rewriting modules together. This tricks logging systems and web applications into thinking the request came from a different source.

Technical detail

When mod_remoteip and mod_rewrite are configured for proxying, an attacker can manipulate request headers to spoof their source IP address. The vulnerability allows bypass of IP-based access controls and falsification of audit logs. Exploitation requires the vulnerable module configuration to be active on the target server.

Summary generated and translated by AI from the official description.
IP address spoofing when proxying using mod_remoteip and mod_rewrite For configurations using proxying with mod_remoteip and certain mod_rewrite rules, an attacker could spoof their IP address for logging and PHP scripts. Note this issue was fixed in Apache HTTP Server 2.4.24 but was retrospectively allocated a low severity CVE in 2020.
Affected products
n/a · Apache HTTP Server

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →