Message view | « Date » · « Thread » |
---|---|
Top | « Date » · « Thread » |
From | Daniel Ruggeri <drugg...@apache.org> |
Subject | CVE-2020-11985: CWE-345: Insufficient verification of data authenticity |
Date | Fri, 07 Aug 2020 11:31:38 GMT |
CVE-2020-11985: CWE-345: Insufficient verification of data authenticity Severity: low Vendor: The Apache Software Foundation Versions Affected: httpd 2.4.1 to 2.4.23 Description: Apache HTTP Server 2.4.1 to 2.4.23 IP address spoofing when proxying using mod_remoteip and mod_rewrite Mitigation: Disable mod_remoteip Credit: Initially reported at https://bugs.launchpad.net/ubuntu/+source/apache2/+bug/1875299 References: https://httpd.apache.org/security/vulnerabilities_24.html | |
Mime |
|
View raw message |