Apache2: In Apache HTTP Server 2.4.0 to 2.4.41, mod_proxy_ftp may use uninitialized memory when proxying to a malicious FTP server.
Apache HTTP Server versions 2.4.0 through 2.4.41 contain a vulnerability in the mod_proxy_ftp module where uninitialized memory may be used when proxying to a malicious FTP server. This issue could lead to information disclosure but does not affect integrity or availability. The vulnerability affects multiple Ubuntu package versions of Apache 2.4.x. No known exploits are reported in the wild.
AI Analysis
Technical Summary
In Apache HTTP Server versions 2.4.0 to 2.4.41, the mod_proxy_ftp module may use uninitialized memory when acting as a proxy to a malicious FTP server. This behavior can result in the exposure of potentially sensitive memory contents. The issue is specific to the mod_proxy_ftp component and occurs during proxy operations. The vulnerability has been identified in numerous Ubuntu package versions of Apache 2.4. No evidence of active exploitation is currently known.
Potential Impact
The vulnerability may allow an attacker controlling a malicious FTP server to cause the Apache HTTP Server's mod_proxy_ftp module to use uninitialized memory, potentially leading to limited information disclosure. There is no indication of impact on integrity or availability. No known exploits in the wild have been reported.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Users should monitor official Ubuntu and Apache advisories for updates and apply patches when available. Until patched, avoid proxying to untrusted or malicious FTP servers with mod_proxy_ftp enabled.
Apache2: In Apache HTTP Server 2.4.0 to 2.4.41, mod_proxy_ftp may use uninitialized memory when proxying to a malicious FTP server.
Description
Apache HTTP Server versions 2.4.0 through 2.4.41 contain a vulnerability in the mod_proxy_ftp module where uninitialized memory may be used when proxying to a malicious FTP server. This issue could lead to information disclosure but does not affect integrity or availability. The vulnerability affects multiple Ubuntu package versions of Apache 2.4.x. No known exploits are reported in the wild.
CVSS v3.1
Score 5.3medium
Affected software
pkg:deb/ubuntu/[email protected]+esm15?arch=source&distro=esm-infra-legacy/trustypkg:deb/ubuntu/[email protected]?arch=source&distro=xenialpkg:deb/ubuntu/[email protected]?arch=source&distro=bionicpkg:deb/ubuntu/[email protected]?arch=source&distro=focalRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
In Apache HTTP Server versions 2.4.0 to 2.4.41, the mod_proxy_ftp module may use uninitialized memory when acting as a proxy to a malicious FTP server. This behavior can result in the exposure of potentially sensitive memory contents. The issue is specific to the mod_proxy_ftp component and occurs during proxy operations. The vulnerability has been identified in numerous Ubuntu package versions of Apache 2.4. No evidence of active exploitation is currently known.
Potential Impact
The vulnerability may allow an attacker controlling a malicious FTP server to cause the Apache HTTP Server's mod_proxy_ftp module to use uninitialized memory, potentially leading to limited information disclosure. There is no indication of impact on integrity or availability. No known exploits in the wild have been reported.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Users should monitor official Ubuntu and Apache advisories for updates and apply patches when available. Until patched, avoid proxying to untrusted or malicious FTP servers with mod_proxy_ftp enabled.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- UBUNTU-CVE-2020-1934
- Osv Schema Version
- 1.7.0
- Ecosystems
- ["Ubuntu:Pro:14.04:LTS","Ubuntu:16.04:LTS","Ubuntu:18.04:LTS","Ubuntu:20.04:LTS"]
- Cvss Version
- 3.1
Threat ID: 6a61512c9c2644c7f8da70ab
Added to database: 07/22/2026, 23:24:28 UTC
Last enriched: 07/23/2026, 00:04:46 UTC
Last updated: 09/10/2026, 19:36:46 UTC
Views: 33
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.