cbcvebase.
CVE-2014-0117
published 2014-07-20

CVE-2014-0117: The mod_proxy module in the Apache HTTP Server 2.4.x before 2.4.10, when a reverse proxy is enabled, allows remote attackers to cause a denial of service…

PriorityP432medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
35.54%
98.3th percentile
The mod_proxy module in the Apache HTTP Server 2.4.x before 2.4.10, when a reverse proxy is enabled, allows remote attackers to cause a denial of service (child-process crash) via a crafted HTTP Connection header.

Affected

7 ranges
VendorProductVersion rangeFixed in
apachehttp_server
apachehttp_server
apachehttp_server
apachehttp_server
applemac_os_x<= 10.10.2
appleos_x_yosemite_v10.10.3_and_security_update_2015-004
debianapache2< apache2 2.4.10-1 (bookworm)apache2 2.4.10-1 (bookworm)

Detection & IOCsextracted from sources · hover to see the quote

  • The vulnerability is triggered via a crafted HTTP Connection header sent to an Apache httpd 2.4.x reverse proxy. Detection should focus on anomalous or malformed Connection header values in requests destined for reverse proxy endpoints.
  • Only Apache httpd versions 2.4.6 through 2.4.9 contain the vulnerable code in mod_proxy. Scope detection/patching efforts to those specific versions.
  • The flaw is in the mod_proxy module. Ensure mod_proxy is only loaded when necessary, and monitor for child-process crash events (e.g., systemd/service failure logs) on servers running httpd 2.4.6–2.4.9 with reverse proxy enabled.
  • ·Vulnerability only affects Apache httpd 2.4.x (specifically 2.4.6–2.4.9) with mod_proxy enabled in reverse proxy mode. httpd 2.2.x (as shipped with RHEL 5/6, JBoss products) is NOT affected.
  • ·The DoS impact is amplified in threaded MPM configurations. Non-threaded MPM deployments may have different crash behavior but are still considered vulnerable.
  • ·On Ubuntu, this issue only affected Ubuntu 14.04 LTS; other Ubuntu releases were not impacted.

CVSS provenance

nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.