CVE-2011-3368 describes a vulnerability in the mod_proxy module of Apache HTTP Server versions 1.3.x, 2.0.x, and 2.2.x. This flaw allows remote attackers to bypass reverse proxy configurations, specifically RewriteRule and ProxyPassMatch patterns, by crafting a malformed URI starting with an '@' character, enabling requests to internal intranet servers. With a CVSS score of 5.0, this vulnerability is easily exploitable over the network with no authentication required, potentially leading to information disclosure. While not listed on CISA's KEV catalog, exploit modules are available in Metasploit and ExploitDB, indicating public awareness of exploitation methods, despite limited community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.3CPE matchmatch criteria | cpe:2.3:a:apache:http_server:1.3:*:*:*:*:*:*:* | ||
1.3.0CPE matchmatch criteria | cpe:2.3:a:apache:http_server:1.3.0:*:*:*:*:*:*:* | ||
1.3.1CPE matchmatch criteria | cpe:2.3:a:apache:http_server:1.3.1:*:*:*:*:*:*:* | ||
1.3.1.1CPE matchmatch criteria | cpe:2.3:a:apache:http_server:1.3.1.1:*:*:*:*:*:*:* | ||
1.3.2CPE matchmatch criteria | cpe:2.3:a:apache:http_server:1.3.2:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.