Apache2: IP address spoofing when proxying using mod_remoteip and mod_rewrite For configurations using proxying with mod_remoteip and certain mod_rewrite…
A vulnerability in Apache HTTP Server allows IP address spoofing when proxying using mod_remoteip combined with certain mod_rewrite rules. This can cause an attacker to spoof their IP address in logs and PHP scripts. The issue was fixed in Apache HTTP Server version 2.4.24 and was assigned a low severity CVE in 2020.
AI Analysis
Technical Summary
The vulnerability allows an attacker to spoof their IP address in environments where Apache HTTP Server is configured to proxy requests using mod_remoteip along with specific mod_rewrite rules. This spoofing affects the IP address recorded in logs and visible to PHP scripts, potentially misleading IP-based access controls or auditing. The flaw was addressed in Apache HTTP Server 2.4.24. The CVE was assigned a low severity rating, reflecting limited impact on confidentiality and availability, with integrity impact limited to spoofing of IP address information.
Potential Impact
An attacker can spoof the client IP address as seen by the server's logging and PHP scripts, which may affect IP-based access controls, logging accuracy, and auditing. There is no direct impact on confidentiality or availability. The integrity impact is limited to falsifying IP address information.
Mitigation Recommendations
A fix is available in Apache HTTP Server version 2.4.24. Users should upgrade to version 2.4.24 or later to remediate this vulnerability. No other specific mitigations are indicated.
Apache2: IP address spoofing when proxying using mod_remoteip and mod_rewrite For configurations using proxying with mod_remoteip and certain mod_rewrite…
Description
A vulnerability in Apache HTTP Server allows IP address spoofing when proxying using mod_remoteip combined with certain mod_rewrite rules. This can cause an attacker to spoof their IP address in logs and PHP scripts. The issue was fixed in Apache HTTP Server version 2.4.24 and was assigned a low severity CVE in 2020.
CVSS v3.1
Affected software
pkg:deb/ubuntu/[email protected]+esm15?arch=source&distro=esm-infra-legacy/trustypkg:deb/ubuntu/[email protected]?arch=source&distro=xenialRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability allows an attacker to spoof their IP address in environments where Apache HTTP Server is configured to proxy requests using mod_remoteip along with specific mod_rewrite rules. This spoofing affects the IP address recorded in logs and visible to PHP scripts, potentially misleading IP-based access controls or auditing. The flaw was addressed in Apache HTTP Server 2.4.24. The CVE was assigned a low severity rating, reflecting limited impact on confidentiality and availability, with integrity impact limited to spoofing of IP address information.
Potential Impact
An attacker can spoof the client IP address as seen by the server's logging and PHP scripts, which may affect IP-based access controls, logging accuracy, and auditing. There is no direct impact on confidentiality or availability. The integrity impact is limited to falsifying IP address information.
Mitigation Recommendations
A fix is available in Apache HTTP Server version 2.4.24. Users should upgrade to version 2.4.24 or later to remediate this vulnerability. No other specific mitigations are indicated.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- UBUNTU-CVE-2020-11985
- Osv Schema Version
- 1.7.0
- Aliases
- []
- Ecosystems
- ["Ubuntu:Pro:14.04:LTS","Ubuntu:16.04:LTS"]
- Database Specific Severity
- null
- Cvss Version
- 3.1
Threat ID: 6a61512c9c2644c7f8da70a4
Added to database: 07/22/2026, 23:24:28 UTC
Last enriched: 07/23/2026, 00:04:25 UTC
Last updated: 07/23/2026, 02:39:34 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.