CVE-2011-3368
Summary
| CVE | CVE-2011-3368 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2011-10-05 22:55:02 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21 does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern matches for configuration of a reverse proxy, which allows remote attackers to send requests to intranet servers via a malformed URI containing an initial @ (at sign) character. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Http Server | 1.3 | All | All | All |
| Application | Apache | Http Server | 1.3.0 | All | All | All |
| Application | Apache | Http Server | 1.3.1 | All | All | All |
| Application | Apache | Http Server | 1.3.1.1 | All | All | All |
| Application | Apache | Http Server | 1.3.10 | All | All | All |
| Application | Apache | Http Server | 1.3.11 | All | All | All |
| Application | Apache | Http Server | 1.3.12 | All | All | All |
| Application | Apache | Http Server | 1.3.13 | All | All | All |
| Application | Apache | Http Server | 1.3.14 | All | All | All |
| Application | Apache | Http Server | 1.3.15 | All | All | All |
| Application | Apache | Http Server | 1.3.16 | All | All | All |
| Application | Apache | Http Server | 1.3.17 | All | All | All |
| Application | Apache | Http Server | 1.3.18 | All | All | All |
| Application | Apache | Http Server | 1.3.19 | All | All | All |
| Application | Apache | Http Server | 1.3.2 | All | All | All |
| Application | Apache | Http Server | 1.3.20 | All | All | All |
| Application | Apache | Http Server | 1.3.22 | All | All | All |
| Application | Apache | Http Server | 1.3.23 | All | All | All |
| Application | Apache | Http Server | 1.3.24 | All | All | All |
| Application | Apache | Http Server | 1.3.25 | All | All | All |
| Application | Apache | Http Server | 1.3.26 | All | All | All |
| Application | Apache | Http Server | 1.3.27 | All | All | All |
| Application | Apache | Http Server | 1.3.28 | All | All | All |
| Application | Apache | Http Server | 1.3.29 | All | All | All |
| Application | Apache | Http Server | 1.3.3 | All | All | All |
| Application | Apache | Http Server | 1.3.30 | All | All | All |
| Application | Apache | Http Server | 1.3.31 | All | All | All |
| Application | Apache | Http Server | 1.3.32 | All | All | All |
| Application | Apache | Http Server | 1.3.33 | All | All | All |
| Application | Apache | Http Server | 1.3.34 | All | All | All |
| Application | Apache | Http Server | 1.3.35 | All | All | All |
| Application | Apache | Http Server | 1.3.36 | All | All | All |
| Application | Apache | Http Server | 1.3.37 | All | All | All |
| Application | Apache | Http Server | 1.3.38 | All | All | All |
| Application | Apache | Http Server | 1.3.39 | All | All | All |
| Application | Apache | Http Server | 1.3.4 | All | All | All |
| Application | Apache | Http Server | 1.3.41 | All | All | All |
| Application | Apache | Http Server | 1.3.42 | All | All | All |
| Application | Apache | Http Server | 1.3.5 | All | All | All |
| Application | Apache | Http Server | 1.3.6 | All | All | All |
| Application | Apache | Http Server | 1.3.65 | All | All | All |
| Application | Apache | Http Server | 1.3.68 | All | All | All |
| Application | Apache | Http Server | 1.3.7 | All | All | All |
| Application | Apache | Http Server | 1.3.8 | All | All | All |
| Application | Apache | Http Server | 1.3.9 | All | All | All |
| Application | Apache | Http Server | 2.0 | All | All | All |
| Application | Apache | Http Server | 2.0.28 | All | All | All |
| Application | Apache | Http Server | 2.0.28 | beta | All | All |
| Application | Apache | Http Server | 2.0.32 | All | All | All |
| Application | Apache | Http Server | 2.0.32 | beta | All | All |
| Application | Apache | Http Server | 2.0.34 | beta | All | All |
| Application | Apache | Http Server | 2.0.35 | All | All | All |
| Application | Apache | Http Server | 2.0.36 | All | All | All |
| Application | Apache | Http Server | 2.0.37 | All | All | All |
| Application | Apache | Http Server | 2.0.38 | All | All | All |
| Application | Apache | Http Server | 2.0.39 | All | All | All |
| Application | Apache | Http Server | 2.0.40 | All | All | All |
| Application | Apache | Http Server | 2.0.41 | All | All | All |
| Application | Apache | Http Server | 2.0.42 | All | All | All |
| Application | Apache | Http Server | 2.0.43 | All | All | All |
| Application | Apache | Http Server | 2.0.44 | All | All | All |
| Application | Apache | Http Server | 2.0.45 | All | All | All |
| Application | Apache | Http Server | 2.0.46 | All | All | All |
| Application | Apache | Http Server | 2.0.47 | All | All | All |
| Application | Apache | Http Server | 2.0.48 | All | All | All |
| Application | Apache | Http Server | 2.0.49 | All | All | All |
| Application | Apache | Http Server | 2.0.50 | All | All | All |
| Application | Apache | Http Server | 2.0.51 | All | All | All |
| Application | Apache | Http Server | 2.0.52 | All | All | All |
| Application | Apache | Http Server | 2.0.53 | All | All | All |
| Application | Apache | Http Server | 2.0.54 | All | All | All |
| Application | Apache | Http Server | 2.0.55 | All | All | All |
| Application | Apache | Http Server | 2.0.56 | All | All | All |
| Application | Apache | Http Server | 2.0.57 | All | All | All |
| Application | Apache | Http Server | 2.0.58 | All | All | All |
| Application | Apache | Http Server | 2.0.59 | All | All | All |
| Application | Apache | Http Server | 2.0.60 | All | All | All |
| Application | Apache | Http Server | 2.0.61 | All | All | All |
| Application | Apache | Http Server | 2.0.63 | All | All | All |
| Application | Apache | Http Server | 2.0.64 | All | All | All |
| Application | Apache | Http Server | 2.0.9 | All | All | All |
| Application | Apache | Http Server | 2.2.0 | All | All | All |
| Application | Apache | Http Server | 2.2.1 | All | All | All |
| Application | Apache | Http Server | 2.2.10 | All | All | All |
| Application | Apache | Http Server | 2.2.11 | All | All | All |
| Application | Apache | Http Server | 2.2.12 | All | All | All |
| Application | Apache | Http Server | 2.2.13 | All | All | All |
| Application | Apache | Http Server | 2.2.14 | All | All | All |
| Application | Apache | Http Server | 2.2.15 | All | All | All |
| Application | Apache | Http Server | 2.2.16 | All | All | All |
| Application | Apache | Http Server | 2.2.18 | All | All | All |
| Application | Apache | Http Server | 2.2.19 | All | All | All |
| Application | Apache | Http Server | 2.2.2 | All | All | All |
| Application | Apache | Http Server | 2.2.20 | All | All | All |
| Application | Apache | Http Server | 2.2.21 | All | All | All |
| Application | Apache | Http Server | 2.2.3 | All | All | All |
| Application | Apache | Http Server | 2.2.4 | All | All | All |
| Application | Apache | Http Server | 2.2.6 | All | All | All |
| Application | Apache | Http Server | 2.2.8 | All | All | All |
| Application | Apache | Http Server | 2.2.9 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Oracle Critical Patch Update - July 2012 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | |
| Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| Debian -- Security Information -- DSA-2405-1 apache2 | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| Security Alerts - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| Full Disclosure: Apache HTTP Server: mod_proxy reverse proxy exposure (CVE-2011-3368) | af854a3a-2127-422b-91ae-364da2661108 | seclists.org | |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| Apache HTTP Server 'mod_proxy' Reverse Proxy Information Disclosure Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| IBM SE49723 - HTTPSVR - PATCH APACHE VULNERABILITY CVE-2011-3368 - United States | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| Advisory: mod_proxy reverse proxy exposure (CVE-2011-3368) - announce.httpd.apache.org - ArchiveOrange | af854a3a-2127-422b-91ae-364da2661108 | web.archiveorange.com | Exploit, Patch |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| '[security bulletin] HPSBMU02748 SSRT100772 rev.1 - HP OpenView Network Node Manager (OV NNM) Running' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| access.redhat.com | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| openSUSE-SU-2013:0248-1: moderate: update for apache2 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| About the security content of OS X Mountain Lion v10.8.2, OS X Lion v10.7.5 and Security Update 2012-004 | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | |
| [Apache-SVN] Revision 1179239 | af854a3a-2127-422b-91ae-364da2661108 | svn.apache.org | Patch |
| openSUSE-SU-2013:0243-1: moderate: update for apache2 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Full Disclosure: Context IS Advisory - Apache Reverse Proxy Bypass Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | seclists.org | |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| [security-announce] SUSE-SU-2011:1229-1: important: Security update for | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| IBM SE49724 - HTTPSVR - PATCH APACHE VULNERABILITY CVE-2011-3368 - United States | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | |
| Apache mod_proxy Reverse Proxy Exposure Vulnerability PoC | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | |
| Support / Security / Advisories / / MDVSA-2011:144 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| Context | af854a3a-2127-422b-91ae-364da2661108 | www.contextis.com | |
| Support / Security / Advisories / / MDVSA-2013:150 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| osvdb.org/76079 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| access.redhat.com | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| About Secunia Research | Flexera | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| '[security bulletin] HPSBOV02822 SSRT100966 rev.1 - HP Secure Web Server (SWS) for OpenVMS, Remote De' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| Juniper Networks - 2013-08 Security Bulletin: Junos Space: Multiple Vulnerabilities - Knowledge Base | af854a3a-2127-422b-91ae-364da2661108 | kb.juniper.net | |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| Oracle Critical Patch Update - January 2015 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | |
| Bug 740045 – CVE-2011-3368 httpd: reverse web proxy vulnerability | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | Exploit, Patch |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| Apache mod_proxy Pattern Matching Bug Lets Remote Users Access Internal Servers - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| APPLE-SA-2012-09-19-2 OS X Mountain Lion v10.8.2, OS X Lion v10.7.5 and Security Update 2012-004 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | |
| About Secunia Research | Flexera | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.