CVE-2011-3368
apache2 - multiple issues
EPSS 90.7%
描述
The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21 does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern matches for configuration of a reverse proxy, which allows remote attackers to send requests to intranet servers via a malformed URI containing an initial @ (at sign) character.
如何修補 CVE-2011-3368
要修補 CVE-2011-3368,請將受影響套件升級到下列已修補版本。
- Debian/apache2—升級至 2.2.21-2 或更新版本
- Debian/apache2—升級至 2.2.16-6+squeeze6 或更新版本
CVE-2011-3368 正在被利用嗎?
可能 — EPSS 為 90.7%,屬於高被利用機率區間,建議優先修補。
受影響套件(2)
- from 0, < 2.2.21-2
- from 0, < 2.2.16-6+squeeze6