CVE-2020-1934 is a medium-severity vulnerability affecting Apache HTTP Server versions 2.4.0 to 2.4.41, as well as various distributions like Canonical, Debian, and Fedora. The flaw lies in mod_proxy_ftp, which can use uninitialized memory when proxying to a malicious FTP server. This could lead to information disclosure (CVSS: 5.3, C:L), though the impact is limited to confidentiality. While the vulnerability has a high FAUCET Risk Score of 93/100 and an EPSS score indicating higher than 95% of all CVEs, there is no evidence of active exploitation in the wild, nor are there publicly available exploit modules like Metasploit or Nuclei. Community discussion and media coverage are minimal, with only one mention and one article found, which incidentally discusses a different Apache vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.4.0, <= 2.4.41CPE matchmatch criteria | cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:* | ||
31CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:* | ||
32CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project
Mar 2, 2026Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project
Dec 10, 2025httpd: mod_proxy_ftp use of uninitialized value
Apr 1, 2020Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project