suse · CVE-2011-4317

Quick triage

Priority: medium Published: 2021-05-30 13:00:36 UTC Updated: 2026-04-18 19:56:01 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2011-4317 severity moderate: SUSE including 93 source package names (apache2-2.2.12-1.28.1, apache2-2.2.12-1.38.2, …), 123 product×package rows across 25 product lines (SUSE Linux Enterprise High Performance Computing 12 SP5, SUSE Linux Enterprise Module for Server Applications 15, … (25 product lines)): Fixed 123.

Description:

The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21, when the Revision 1179239 patch is in place, does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern matches for configuration of a reverse proxy, which allows remote attackers to send requests to intranet servers via a malformed URI containing an @ (at sign) character and a : (colon) character in invalid positions. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-3368.

cvelogic Threat Intelligence