CVE-2020-11985 describes an IP address spoofing vulnerability in Apache HTTP Server, specifically affecting configurations utilizing mod_remoteip and mod_rewrite for proxying. An attacker could manipulate their apparent IP address in logs and PHP scripts. This medium-severity vulnerability (CVSS 5.3) has a low attack complexity and requires no user interaction, but its impact is limited to integrity (spoofing IP addresses) and does not lead to confidentiality or availability issues. While the issue was fixed in Apache HTTP Server 2.4.24, it was retrospectively assigned a CVE in 2020. There is no evidence of active exploitation, public exploit code, or significant community discussion, and it is not listed on the CISA KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.4.1, <= 2.4.23CPE matchmatch criteria | cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project
Mar 2, 2026Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project
Dec 10, 2025httpd: IP address spoofing when proxying using mod_remoteip and mod_rewrite
Aug 7, 2020Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project