2017-10-16 12:31:07 -04:00
{
2019-03-17 23:37:27 +00:00
"CVE_data_meta" : {
"ASSIGNER" : "secalert@redhat.com" ,
"ID" : "CVE-2011-3368" ,
"STATE" : "PUBLIC"
} ,
"affects" : {
"vendor" : {
"vendor_data" : [
{
"product" : {
"product_data" : [
{
"product_name" : "n/a" ,
"version" : {
"version_data" : [
{
"version_value" : "n/a"
}
]
}
}
]
} ,
"vendor_name" : "n/a"
}
2017-10-16 12:31:07 -04:00
]
2019-03-17 23:37:27 +00:00
}
} ,
"data_format" : "MITRE" ,
"data_type" : "CVE" ,
"data_version" : "4.0" ,
"description" : {
"description_data" : [
{
"lang" : "eng" ,
"value" : "The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21 does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern matches for configuration of a reverse proxy, which allows remote attackers to send requests to intranet servers via a malformed URI containing an initial @ (at sign) character."
}
]
} ,
"problemtype" : {
"problemtype_data" : [
{
"description" : [
{
"lang" : "eng" ,
"value" : "n/a"
}
]
}
]
} ,
"references" : {
"reference_data" : [
{
"name" : "[announce] 20111005 Advisory: mod_proxy reverse proxy exposure (CVE-2011-3368)" ,
"refsource" : "MLIST" ,
"url" : "http://web.archiveorange.com/archive/v/ZyS0hzECD5zzb2NkvQlt"
} ,
{
"name" : "http://svn.apache.org/viewvc?view=revision&revision=1179239" ,
"refsource" : "CONFIRM" ,
"url" : "http://svn.apache.org/viewvc?view=revision&revision=1179239"
} ,
{
"name" : "SSRT100966" ,
"refsource" : "HP" ,
"url" : "http://marc.info/?l=bugtraq&m=134987041210674&w=2"
} ,
{
"name" : "http://www.contextis.com/research/blog/reverseproxybypass/" ,
"refsource" : "MISC" ,
"url" : "http://www.contextis.com/research/blog/reverseproxybypass/"
} ,
{
"name" : "20111005 Context IS Advisory - Apache Reverse Proxy Bypass Vulnerability" ,
"refsource" : "FULLDISC" ,
"url" : "http://seclists.org/fulldisclosure/2011/Oct/273"
} ,
{
"name" : "RHSA-2011:1391" ,
"refsource" : "REDHAT" ,
"url" : "http://www.redhat.com/support/errata/RHSA-2011-1391.html"
} ,
{
"name" : "SE49724" ,
"refsource" : "AIXAPAR" ,
"url" : "http://www-01.ibm.com/support/docview.wss?uid=nas2b7c57b1f1035675186257927003c8d48"
} ,
{
"name" : "RHSA-2012:0543" ,
"refsource" : "REDHAT" ,
"url" : "http://rhn.redhat.com/errata/RHSA-2012-0543.html"
} ,
{
"name" : "HPSBOV02822" ,
"refsource" : "HP" ,
"url" : "http://marc.info/?l=bugtraq&m=134987041210674&w=2"
} ,
{
"name" : "46288" ,
"refsource" : "SECUNIA" ,
"url" : "http://secunia.com/advisories/46288"
} ,
{
"name" : "76079" ,
"refsource" : "OSVDB" ,
"url" : "http://osvdb.org/76079"
} ,
{
"name" : "17969" ,
"refsource" : "EXPLOIT-DB" ,
"url" : "http://www.exploit-db.com/exploits/17969"
} ,
{
"name" : "SSRT100772" ,
"refsource" : "HP" ,
"url" : "http://marc.info/?l=bugtraq&m=133294460209056&w=2"
} ,
{
"name" : "http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html" ,
"refsource" : "CONFIRM" ,
"url" : "http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html"
} ,
{
"name" : "49957" ,
"refsource" : "BID" ,
"url" : "http://www.securityfocus.com/bid/49957"
} ,
{
"name" : "SE49723" ,
"refsource" : "AIXAPAR" ,
"url" : "http://www-01.ibm.com/support/docview.wss?uid=nas2064c7e5f53452ff686257927003c8d42"
} ,
{
"name" : "HPSBMU02748" ,
"refsource" : "HP" ,
"url" : "http://marc.info/?l=bugtraq&m=133294460209056&w=2"
} ,
{
"name" : "RHSA-2012:0542" ,
"refsource" : "REDHAT" ,
"url" : "http://rhn.redhat.com/errata/RHSA-2012-0542.html"
} ,
{
"name" : "APPLE-SA-2012-09-19-2" ,
"refsource" : "APPLE" ,
"url" : "http://lists.apple.com/archives/security-announce/2012/Sep/msg00004.html"
} ,
{
"name" : "http://support.apple.com/kb/HT5501" ,
"refsource" : "CONFIRM" ,
"url" : "http://support.apple.com/kb/HT5501"
} ,
{
"name" : "apache-modproxy-information-disclosure(70336)" ,
"refsource" : "XF" ,
"url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/70336"
} ,
{
"name" : "http://www.oracle.com/technetwork/topics/security/cpujul2012-392727.html" ,
"refsource" : "CONFIRM" ,
"url" : "http://www.oracle.com/technetwork/topics/security/cpujul2012-392727.html"
} ,
{
"name" : "https://bugzilla.redhat.com/show_bug.cgi?id=740045" ,
"refsource" : "CONFIRM" ,
"url" : "https://bugzilla.redhat.com/show_bug.cgi?id=740045"
} ,
{
"name" : "1026144" ,
"refsource" : "SECTRACK" ,
"url" : "http://www.securitytracker.com/id?1026144"
} ,
{
"name" : "RHSA-2011:1392" ,
"refsource" : "REDHAT" ,
"url" : "http://www.redhat.com/support/errata/RHSA-2011-1392.html"
} ,
{
"name" : "20111005 Apache HTTP Server: mod_proxy reverse proxy exposure (CVE-2011-3368)" ,
"refsource" : "FULLDISC" ,
"url" : "http://seclists.org/fulldisclosure/2011/Oct/232"
} ,
{
"name" : "openSUSE-SU-2013:0248" ,
"refsource" : "SUSE" ,
"url" : "http://lists.opensuse.org/opensuse-updates/2013-02/msg00012.html"
} ,
{
"name" : "MDVSA-2011:144" ,
"refsource" : "MANDRIVA" ,
"url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2011:144"
} ,
{
"name" : "openSUSE-SU-2013:0243" ,
"refsource" : "SUSE" ,
"url" : "http://lists.opensuse.org/opensuse-updates/2013-02/msg00009.html"
} ,
{
"name" : "MDVSA-2013:150" ,
"refsource" : "MANDRIVA" ,
"url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2013:150"
} ,
{
"name" : "46414" ,
"refsource" : "SECUNIA" ,
"url" : "http://secunia.com/advisories/46414"
} ,
{
"name" : "48551" ,
"refsource" : "SECUNIA" ,
"url" : "http://secunia.com/advisories/48551"
} ,
{
"name" : "DSA-2405" ,
"refsource" : "DEBIAN" ,
"url" : "http://www.debian.org/security/2012/dsa-2405"
} ,
{
"name" : "SUSE-SU-2011:1229" ,
"refsource" : "SUSE" ,
"url" : "http://lists.opensuse.org/opensuse-security-announce/2011-11/msg00011.html"
} ,
{
"name" : "http://kb.juniper.net/JSA10585" ,
"refsource" : "CONFIRM" ,
"url" : "http://kb.juniper.net/JSA10585"
2019-08-15 09:00:49 +00:00
} ,
{
"refsource" : "MLIST" ,
"name" : "[httpd-cvs] 20190815 svn commit: r1048742 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html" ,
"url" : "https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac@%3Ccvs.httpd.apache.org%3E"
} ,
{
"refsource" : "MLIST" ,
"name" : "[httpd-cvs] 20190815 svn commit: r1048743 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html" ,
"url" : "https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79@%3Ccvs.httpd.apache.org%3E"
2019-03-17 23:37:27 +00:00
}
]
}
}