httpd: reverse web proxy vulnerability
Published Oct 5, 2011
5.0
MEDIUMCVSS 2.0
EPSS 90.73%
Description
The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21 does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern matches for configuration of a reverse proxy, which allows remote attackers to send requests to intranet servers via a malformed URI containing an initial @ (at sign) character.
Affected products
No data.
Configuration 1
- 1.3
- 1.3.0
- 1.3.1
- 1.3.1.1
- 1.3.2
- 1.3.3
- 1.3.4
- 1.3.5
- 1.3.6
- 1.3.7
- 1.3.8
- 1.3.9
- 1.3.10
- 1.3.11
- 1.3.12
- 1.3.13
- 1.3.14
- 1.3.15
- 1.3.16
- 1.3.17
- 1.3.18
- 1.3.19
- 1.3.20
- 1.3.22
- 1.3.23
- 1.3.24
- 1.3.25
- 1.3.26
- 1.3.27
- 1.3.28
- 1.3.29
- 1.3.30
- 1.3.31
- 1.3.32
- 1.3.33
- 1.3.34
- 1.3.35
- 1.3.36
- 1.3.37
- 1.3.38
- 1.3.39
- 1.3.41
- 1.3.42
- 1.3.65
- 1.3.68
Configuration 2
- 2.0
- 2.0.9
- 2.0.28
- 2.0.28
- 2.0.32
- 2.0.32
- 2.0.34
- 2.0.35
- 2.0.36
- 2.0.37
- 2.0.38
- 2.0.39
- 2.0.40
- 2.0.41
- 2.0.42
- 2.0.43
- 2.0.44
- 2.0.45
- 2.0.46
- 2.0.47
- 2.0.48
- 2.0.49
- 2.0.50
- 2.0.51
- 2.0.52
- 2.0.53
- 2.0.54
- 2.0.55
- 2.0.56
- 2.0.57
- 2.0.58
- 2.0.59
- 2.0.60
- 2.0.61
- 2.0.63
- 2.0.64
Configuration 3
- 2.2.0
- 2.2.1
- 2.2.2
- 2.2.3
- 2.2.4
- 2.2.6
- 2.2.8
- 2.2.9
- 2.2.10
- 2.2.11
- 2.2.12
- 2.2.13
- 2.2.14
- 2.2.15
- 2.2.16
- 2.2.18
- 2.2.19
- 2.2.20
- 2.2.21
No data.
Red Hat Enterprise Linux 4
httpd-0:2.0.52-49.ent
Fixed · RHSA-2011:1392
Red Hat Enterprise Linux 5
httpd-0:2.2.3-53.el5_7.3
Fixed · RHSA-2011:1392
Red Hat Enterprise Linux 6
httpd-0:2.2.15-9.el6_1.3
Fixed · RHSA-2011:1391
Red Hat JBoss Enterprise Web Server 1 for RHEL 5
httpd-0:2.2.17-15.4.ep5.el5
Fixed · RHSA-2012:0542
Red Hat JBoss Enterprise Web Server 1 for RHEL 6
httpd-0:2.2.17-15.4.ep5.el6
Fixed · RHSA-2012:0542
Red Hat JBoss Web Server 1.0
n/a
Fixed · RHSA-2012:0543
Red Hat Directory Server 8
httpd
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 4 | httpd-0:2.0.52-49.ent | Fixed | RHSA-2011:1392 |
| Red Hat Enterprise Linux 5 | httpd-0:2.2.3-53.el5_7.3 | Fixed | RHSA-2011:1392 |
| Red Hat Enterprise Linux 6 | httpd-0:2.2.15-9.el6_1.3 | Fixed | RHSA-2011:1391 |
| Red Hat JBoss Enterprise Web Server 1 for RHEL 5 | httpd-0:2.2.17-15.4.ep5.el5 | Fixed | RHSA-2012:0542 |
| Red Hat JBoss Enterprise Web Server 1 for RHEL 6 | httpd-0:2.2.17-15.4.ep5.el6 | Fixed | RHSA-2012:0542 |
| Red Hat JBoss Web Server 1.0 | n/a | Fixed | RHSA-2012:0543 |
| Red Hat Directory Server 8 | httpd | Will not fix | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:P/I:N/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (43 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 90.73% (0.90734) | 99.80th | v5 (v2026.06.15) |
| Jun 15, 2026 | 90.73% (0.90734) | 99.79th | v5 (v2026.06.15) |
| Jun 14, 2026 | 74.45% (0.74448) | 98.87th | v4 (v2025.03.14) |
| Jun 13, 2026 | 72.54% (0.72537) | 98.79th | v4 (v2025.03.14) |
| Apr 25, 2026 | 76.89% (0.76893) | 98.97th | v4 (v2025.03.14) |
| Jan 4, 2026 | 79.13% (0.79132) | 99.02th | v4 (v2025.03.14) |
| Jan 1, 2026 | 80.17% (0.80173) | 99.09th | v4 (v2025.03.14) |
| Dec 4, 2025 | 79.13% (0.79132) | 99.01th | v4 (v2025.03.14) |
| Dec 1, 2025 | 80.17% (0.80173) | 99.07th | v4 (v2025.03.14) |
| Nov 4, 2025 | 79.13% (0.79132) | 99.02th | v4 (v2025.03.14) |
| Nov 1, 2025 | 80.17% (0.80173) | 99.07th | v4 (v2025.03.14) |
| Oct 4, 2025 | 79.13% (0.79132) | 99.03th | v4 (v2025.03.14) |
| Oct 1, 2025 | 80.17% (0.80173) | 99.08th | v4 (v2025.03.14) |
| Jul 4, 2025 | 79.13% (0.79132) | 99.00th | v4 (v2025.03.14) |
| Jul 1, 2025 | 80.17% (0.80173) | 99.06th | v4 (v2025.03.14) |
| Jun 4, 2025 | 79.13% (0.79132) | 99.00th | v4 (v2025.03.14) |
| Jun 1, 2025 | 80.17% (0.80173) | 99.06th | v4 (v2025.03.14) |
| May 4, 2025 | 79.13% (0.79132) | 98.99th | v4 (v2025.03.14) |
| May 1, 2025 | 80.17% (0.80173) | 99.04th | v4 (v2025.03.14) |
| Mar 30, 2025 | 79.13% (0.79132) | 99.01th | v4 (v2025.03.14) |
| Mar 29, 2025 | 83.24% (0.83243) | 99.08th | v4 (v2025.03.14) |
| Mar 28, 2025 | 79.13% (0.79132) | 99.00th | v4 (v2025.03.14) |
| Mar 27, 2025 | 83.24% (0.83243) | 99.20th | v4 (v2025.03.14) |
| Mar 20, 2025 | 79.13% (0.79132) | 99.05th | v4 (v2025.03.14) |
| Mar 19, 2025 | 83.24% (0.83243) | 99.22th | v4 (v2025.03.14) |
| Mar 17, 2025 | 80.35% (0.80350) | 99.08th | v4 (v2025.03.14) |
| Dec 12, 2024 | 97.22% (0.97222) | 99.87th | v3 (v2023.03.01) |
| Jul 14, 2024 | 97.39% (0.97386) | 99.92th | v3 (v2023.03.01) |
| May 25, 2024 | 97.40% (0.97402) | 99.92th | v3 (v2023.03.01) |
| Feb 11, 2024 | 97.32% (0.97321) | 99.86th | v3 (v2023.03.01) |
| Feb 8, 2024 | 97.40% (0.97401) | 99.91th | v3 (v2023.03.01) |
| Dec 18, 2023 | 97.39% (0.97386) | 99.90th | v3 (v2023.03.01) |
| Oct 24, 2023 | 97.40% (0.97403) | 99.90th | v3 (v2023.03.01) |
| Aug 31, 2023 | 97.37% (0.97371) | 99.85th | v3 (v2023.03.01) |
| Jul 8, 2023 | 97.36% (0.97364) | 99.83th | v3 (v2023.03.01) |
| Jul 4, 2023 | 97.33% (0.97330) | 99.80th | v3 (v2023.03.01) |
| May 8, 2023 | 97.38% (0.97377) | 99.83th | v3 (v2023.03.01) |
| May 5, 2023 | 97.43% (0.97434) | 99.89th | v3 (v2023.03.01) |
| Mar 7, 2023 | 97.45% (0.97449) | 99.89th | v3 (v2023.03.01) |
| Mar 6, 2023 | 83.15% (0.83146) | 99.59th | v2 (v2022.01.01) |
| Feb 10, 2023 | 83.15% (0.83146) | 99.59th | v2 (v2022.01.01) |
| Nov 25, 2022 | 88.70% (0.88697) | 99.80th | v2 (v2022.01.01) |
| Feb 4, 2022 | 92.05% (0.92045) | 99.88th | v2 (v2022.01.01) |
References (58)
- http://kb.juniper.net/JSA10585 x_refsource_CONFIRM
- http://lists.apple.com/archives/security-announce/2012/Sep/msg00004.html vendor-advisoryx_refsource_APPLE
- http://lists.opensuse.org/opensuse-security-announce/2011-11/msg00011.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-updates/2013-02/msg00009.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-updates/2013-02/msg00012.html vendor-advisoryx_refsource_SUSE
- http://marc.info/?l=bugtraq&m=133294460209056&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=134987041210674&w=2 vendor-advisoryx_refsource_HP
- http://osvdb.org/76079 vdb-entryx_refsource_OSVDB
- http://rhn.redhat.com/errata/RHSA-2012-0542.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2012-0543.html vendor-advisoryx_refsource_REDHAT
- http://seclists.org/fulldisclosure/2011/Oct/232 mailing-listx_refsource_FULLDISC
- http://seclists.org/fulldisclosure/2011/Oct/273 mailing-listx_refsource_FULLDISC
- http://secunia.com/advisories/46288 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/46414 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/48551 third-party-advisoryx_refsource_SECUNIA
- http://support.apple.com/kb/HT5501 x_refsource_CONFIRM
- http://svn.apache.org/viewvc?view=revision&revision=1179239 x_refsource_CONFIRMPatch
- http://web.archiveorange.com/archive/v/ZyS0hzECD5zzb2NkvQlt mailing-listx_refsource_MLISTExploitPatch
- http://www-01.ibm.com/support/docview.wss?uid=nas2064c7e5f53452ff686257927003c8d42 vendor-advisoryx_refsource_AIXAPAR
- http://www-01.ibm.com/support/docview.wss?uid=nas2b7c57b1f1035675186257927003c8d48 vendor-advisoryx_refsource_AIXAPAR
- http://www.contextis.com/research/blog/reverseproxybypass/ x_refsource_MISC
- http://www.debian.org/security/2012/dsa-2405 vendor-advisoryx_refsource_DEBIAN
- http://www.exploit-db.com/exploits/17969 exploitx_refsource_EXPLOIT-DB
- http://www.mandriva.com/security/advisories?name=MDVSA-2011:144 vendor-advisoryx_refsource_MANDRIVA
- http://www.mandriva.com/security/advisories?name=MDVSA-2013:150 vendor-advisoryx_refsource_MANDRIVA
- http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html x_refsource_CONFIRM
- http://www.oracle.com/technetwork/topics/security/cpujul2012-392727.html x_refsource_CONFIRM
- http://www.redhat.com/support/errata/RHSA-2011-1391.html vendor-advisoryx_refsource_REDHAT
- http://www.redhat.com/support/errata/RHSA-2011-1392.html vendor-advisoryx_refsource_REDHAT
- http://www.securityfocus.com/bid/49957 vdb-entryx_refsource_BID
- http://www.securitytracker.com/id?1026144 vdb-entryx_refsource_SECTRACK
- https://access.redhat.com/security/cve/CVE-2011-3368 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=740045 x_refsource_CONFIRMExploitPatchIssue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/70336 vdb-entryx_refsource_XF
- https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r064df0985779b7ee044d3120d71ba59750427cf53f57ba3384e3773f%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r1d201e3da31a2c8aa870c8314623caef7debd74a13d0f25205e26f15%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r5419c9ba0951ef73a655362403d12bb8d10fab38274deb3f005816f5%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r5f9c22f9c28adbd9f00556059edc7b03a5d5bb71d4bb80257c0d34e4%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r688df6f16f141e966a0a47f817e559312b3da27886f59116a94b273d%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rb9c9f42dafa25d2f669dac2a536a03f2575bc5ec1be6f480618aee10%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/re2e23465bbdb17ffe109d21b4f192e6b58221cd7aa8797d530b4cd75%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLIST
- https://nvd.nist.gov/vuln/detail/CVE-2011-3368
- https://www.cve.org/CVERecord?id=CVE-2011-3368
Change history (0)
No recorded changes yet.