CVE-2011-4317 is a security bypass vulnerability affecting the mod_proxy module in Apache HTTP Server versions 1.3.x, 2.0.x, and 2.2.x, specifically when a particular patch (Revision 1179239) is applied. This flaw allows remote attackers to bypass reverse proxy configurations, such as RewriteRule and ProxyPassMatch, by crafting a malformed URI with an "@" and ":" character, enabling access to internal intranet servers. With a CVSS score of 4.3 (medium severity) and an EPSS score of 0.84292, it indicates a moderate risk with a higher-than-average likelihood of exploitation compared to most CVEs. While not listed on the KEV catalog, an exploit is publicly available on ExploitDB, and its FAUCET Risk Score of 98/100 suggests significant potential impact despite minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.3CPE matchmatch criteria | cpe:2.3:a:apache:http_server:1.3:*:*:*:*:*:*:* | ||
1.3.0CPE matchmatch criteria | cpe:2.3:a:apache:http_server:1.3.0:*:*:*:*:*:*:* | ||
1.3.1CPE matchmatch criteria | cpe:2.3:a:apache:http_server:1.3.1:*:*:*:*:*:*:* | ||
1.3.1.1CPE matchmatch criteria | cpe:2.3:a:apache:http_server:1.3.1.1:*:*:*:*:*:*:* | ||
1.3.2CPE matchmatch criteria | cpe:2.3:a:apache:http_server:1.3.2:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:P/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.