cbcvebase.
CVE-2011-3639
published 2011-11-30

CVE-2011-3639: The mod_proxy module in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x before 2.2.18, when the Revision 1179239 patch is in place, does not properly…

PriorityP345medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EXPLOIT
EPSS
50.60%
98.8th percentile
The mod_proxy module in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x before 2.2.18, when the Revision 1179239 patch is in place, does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern matches for configuration of a reverse proxy, which allows remote attackers to send requests to intranet servers by using the HTTP/0.9 protocol with a malformed URI containing an initial @ (at sign) character. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-3368.

Affected

68 ranges· showing 25
VendorProductVersion rangeFixed in
apachehttp_server
apachehttp_server
apachehttp_server
apachehttp_server
apachehttp_server
apachehttp_server
apachehttp_server
apachehttp_server
apachehttp_server
apachehttp_server
apachehttp_server
apachehttp_server
apachehttp_server
apachehttp_server
apachehttp_server
apachehttp_server
apachehttp_server
apachehttp_server
apachehttp_server
apachehttp_server
apachehttp_server
apachehttp_server
apachehttp_server
apachehttp_server
apachehttp_server

Detection & IOCsextracted from sources · hover to see the quote

  • Attackers exploit this vulnerability by sending HTTP/0.9 requests with a malformed URI containing an initial '@' (at sign) character to bypass reverse proxy controls and reach intranet servers.
  • Vulnerable reverse proxy configurations use RewriteRule or ProxyPassMatch with open-ended pattern matches (e.g., ^(.*)); monitor for HTTP/0.9 requests hitting these proxy rules.
  • The vulnerability is an incomplete fix for CVE-2011-3368; systems running Apache 2.0.x through 2.0.64 or 2.2.x before 2.2.18 with the Revision 1179239 patch applied are affected.
  • This problem affects httpd packages in Red Hat Enterprise Linux 4, 5 and 6 that were released to address CVE-2011-3368; check for those specific patched-but-still-vulnerable package versions.
  • ·Vulnerability only manifests when the Revision 1179239 patch (incomplete CVE-2011-3368 fix) is applied to Apache 2.0.x–2.0.64 or 2.2.x before 2.2.18; Apache 2.2.18 and later are not affected.
  • ·Upstream confirmed the additional fix is not required for httpd versions 2.2.18 and later; only pre-2.2.18 installs with the CVE-2011-3368 patch are at risk.
  • ·The attack vector requires the reverse proxy to be configured with open-ended RewriteRule or ProxyPassMatch patterns; tightly scoped proxy patterns reduce exposure.

CVSS provenance

nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.