CVE-2011-3348
published 2011-09-20CVE-2011-3348: The mod_proxy_ajp module in the Apache HTTP Server before 2.2.21, when used with mod_proxy_balancer in certain configurations, allows remote attackers to cause…
PriorityP430medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
22.38%
97.4th percentile
The mod_proxy_ajp module in the Apache HTTP Server before 2.2.21, when used with mod_proxy_balancer in certain configurations, allows remote attackers to cause a denial of service (temporary "error state" in the backend server) via a malformed HTTP request.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | http_server | 2.2.12 – 2.2.20 | — |
| apache | httpd | — | — |
| debian | apache2 | < apache2 2.2.21-1 (bookworm) | apache2 2.2.21-1 (bookworm) |
| redhat | jboss_enterprise_web_server | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
vendor_apache4.3
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vqqq-3xjq-cg84: The mod_proxy_ajp module in the Apache HTTP Server before 2
ghsa_unreviewed·2022-05-13
CVE-2011-3348 [MEDIUM] CWE-400 GHSA-vqqq-3xjq-cg84: The mod_proxy_ajp module in the Apache HTTP Server before 2
The mod_proxy_ajp module in the Apache HTTP Server before 2.2.21, when used with mod_proxy_balancer in certain configurations, allows remote attackers to cause a denial of service (temporary "error state" in the backend server) via a malformed HTTP request.
OSV
CVE-2011-3348: The mod_proxy_ajp module in the Apache HTTP Server before 2
osv·2011-09-20·CVSS 4.3
CVE-2011-3348 [MEDIUM] CVE-2011-3348: The mod_proxy_ajp module in the Apache HTTP Server before 2
The mod_proxy_ajp module in the Apache HTTP Server before 2.2.21, when used with mod_proxy_balancer in certain configurations, allows remote attackers to cause a denial of service (temporary "error state" in the backend server) via a malformed HTTP request.
Ubuntu
Apache vulnerabilities
vendor_ubuntu·2011-11-11·CVSS 4.3
CVE-2011-1176 [MEDIUM] Apache vulnerabilities
Title: Apache vulnerabilities
Summary: Multiple vulnerabilities and a regression were fixed in the Apache HTTP
server.
It was discovered that the mod_proxy module in Apache did not properly
interact with the RewriteRule and ProxyPassMatch pattern matches
in the configuration of a reverse proxy. This could allow remote
attackers to contact internal webservers behind the proxy that were
not intended for external exposure. (CVE-2011-3368)
Stefano Nichele discovered that the mod_proxy_ajp module in Apache when
used with mod_proxy_balancer in certain configurations could allow
remote attackers to cause a denial of service via a malformed HTTP
request. (CVE-2011-3348)
Samuel Montosa discovered that the ITK Multi-Processing Module for
Apache did not properly handle certain configuration secti
Red Hat
httpd: mod_proxy_ajp remote temporary DoS
vendor_redhat·2011-09-14·CVSS 4.3
CVE-2011-3348 [MEDIUM] httpd: mod_proxy_ajp remote temporary DoS
httpd: mod_proxy_ajp remote temporary DoS
The mod_proxy_ajp module in the Apache HTTP Server before 2.2.21, when used with mod_proxy_balancer in certain configurations, allows remote attackers to cause a denial of service (temporary "error state" in the backend server) via a malformed HTTP request.
Statement: This issue did not affect the versions of httpd as shipped with Red Hat Enterprise Linux 4 and 5 as this flaw was introduced in version 2.2.12.
Package: httpd (Red Hat Enterprise Linux 4) - Not affected
Package: httpd (Red Hat Enterprise Linux 5) - Not affected
Debian
CVE-2011-3348: apache2 - The mod_proxy_ajp module in the Apache HTTP Server before 2.2.21, when used with...
vendor_debian·2011·CVSS 4.3
CVE-2011-3348 [MEDIUM] CVE-2011-3348: apache2 - The mod_proxy_ajp module in the Apache HTTP Server before 2.2.21, when used with...
The mod_proxy_ajp module in the Apache HTTP Server before 2.2.21, when used with mod_proxy_balancer in certain configurations, allows remote attackers to cause a denial of service (temporary "error state" in the backend server) via a malformed HTTP request.
Scope: local
bookworm: resolved (fixed in 2.2.21-1)
bullseye: resolved (fixed in 2.2.21-1)
forky: resolved (fixed in 2.2.21-1)
sid: resolved (fixed in 2.2.21-1)
trixie: resolved (fixed in 2.2.21-1)
Apache
Apache httpd: CVE-2011-3348
vendor_apache·CVSS 4.3
CVE-2011-3348 Apache httpd: CVE-2011-3348
Apache httpd: CVE-2011-3348
A flaw was found when mod_proxy_ajp is used together with mod_proxy_balancer. Given a specific configuration, a remote attacker could send certain malformed HTTP requests, putting a backend server into an error state until the retry timeout expired. This could lead to a temporary denial of service. Reported to security team 2011-09-07 Issue public 2011-09-14 Update 2.2.21 released 2011-09-14 Affects 2.2.20, 2.2.19, 2.2.18, 2.2.17, 2.2.16, 2.2.15, 2.2.14, 2.2.13, 2.2.12
Severity: moderate
No detection rules found.
No public exploits indexed.
HackerOne
Out-of-date Version (Apache)
hackerone·2019-12-02·CVSS 5.0
[MEDIUM] Out-of-date Version (Apache)
Out-of-date Version (Apache)
URL https://████████/
Identified Version 2.2.15 (contains 4 important and 10 other vulnerabilities)
Latest Version 2.2.31
Vulnerability Database Result is based on 27.10.2016 vulnerability database content.
Vulnerability Details
Link identified you are using an out-of-date version of Apache.
Impact
Since this is an old version of the software, it may be vulnerable to attacks.
Remedy
Please upgrade your installation of Apache to the latest stable version.
Remedy References
•Downloading the Apache HTTP Server
Known Vulnerabilities in this Version
Medium Apache mod_cache and mod_dav Request Handling Denial of Service Vulnerability
The mod_cache and mod_dav modules in the Apache HTTP Server allow remote attackers to cause a denial of service (process
Bugzilla
CVE-2011-3348 httpd: mod_proxy_ajp remote temporary DoS
bugzilla·2011-09-08·CVSS 4.3
CVE-2011-3348 [MEDIUM] CVE-2011-3348 httpd: mod_proxy_ajp remote temporary DoS
CVE-2011-3348 httpd: mod_proxy_ajp remote temporary DoS
mod_proxy_ajp did not correctly process certain malformed HTTP requests, which could cause it to incorrectly put a backend server to an error state until the retry timeout expired. A remote attacker could send malicious requests to trigger this issue, resulting in a temporary denial of service.
Upstream commit:
http://svn.apache.org/viewvc?view=revision&revision=1166551
Reference:
http://community.jboss.org/message/625307
Discussion:
(In reply to comment #0)
> Upstream commit:
> http://svn.apache.org/viewvc?view=revision&revision=1166551
Replaced by:
http://svn.apache.org/viewvc?view=revision&revision=1166657
---
Public now via upstream httpd release 2.2.21:
http://httpd.apache.org/security/vulnerabilities_22.html#2.2.21
http
http://community.jboss.org/message/625307http://httpd.apache.org/security/vulnerabilities_22.html#2.2.21http://lists.apple.com/archives/security-announce/2012/Feb/msg00000.htmlhttp://marc.info/?l=bugtraq&m=131731002122529&w=2http://marc.info/?l=bugtraq&m=132033751509019&w=2http://rhn.redhat.com/errata/RHSA-2012-0542.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0543.htmlhttp://secunia.com/advisories/46013http://support.apple.com/kb/HT5130http://www.apache.org/dist/httpd/Announcement2.2.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2011:168http://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.htmlhttp://www.redhat.com/support/errata/RHSA-2011-1391.htmlhttp://www.securityfocus.com/bid/49616http://www.securitytracker.com/id?1026054https://exchange.xforce.ibmcloud.com/vulnerabilities/69804https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r1d201e3da31a2c8aa870c8314623caef7debd74a13d0f25205e26f15%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r688df6f16f141e966a0a47f817e559312b3da27886f59116a94b273d%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/re2e23465bbdb17ffe109d21b4f192e6b58221cd7aa8797d530b4cd75%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3Ehttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14941https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18154http://community.jboss.org/message/625307http://httpd.apache.org/security/vulnerabilities_22.html#2.2.21http://lists.apple.com/archives/security-announce/2012/Feb/msg00000.htmlhttp://marc.info/?l=bugtraq&m=131731002122529&w=2http://marc.info/?l=bugtraq&m=132033751509019&w=2http://rhn.redhat.com/errata/RHSA-2012-0542.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0543.htmlhttp://secunia.com/advisories/46013http://support.apple.com/kb/HT5130http://www.apache.org/dist/httpd/Announcement2.2.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2011:168http://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.htmlhttp://www.redhat.com/support/errata/RHSA-2011-1391.htmlhttp://www.securityfocus.com/bid/49616http://www.securitytracker.com/id?1026054https://exchange.xforce.ibmcloud.com/vulnerabilities/69804https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r1d201e3da31a2c8aa870c8314623caef7debd74a13d0f25205e26f15%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r688df6f16f141e966a0a47f817e559312b3da27886f59116a94b273d%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/re2e23465bbdb17ffe109d21b4f192e6b58221cd7aa8797d530b4cd75%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3Ehttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14941https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18154
2011-09-20
Published