CVE-2020-11984

Public Exploit

Description

Apache HTTP server 2.4.32 to 2.4.44 mod_proxy_uwsgi info disclosure and possible RCE

Category

9.8
CVSS
Severity: Critical
CVSS 3.1 •
CVSS 2.0 •
EPSS 50.27% Top 5%
Vendor Advisory gentoo.org Vendor Advisory ubuntu.com Vendor Advisory opensuse.org Vendor Advisory opensuse.org Vendor Advisory fedoraproject.org Vendor Advisory debian.org Vendor Advisory fedoraproject.org Vendor Advisory openwall.com Vendor Advisory apache.org
Affected: n/a Apache HTTP Server
Published at:
Updated at:

References

Link Tags
https://httpd.apache.org/security/vulnerabilities_24.html vendor advisory
http://www.openwall.com/lists/oss-security/2020/08/08/1 third party advisory mailing list
https://security.gentoo.org/glsa/202008-04 third party advisory vendor advisory
http://www.openwall.com/lists/oss-security/2020/08/08/10 third party advisory mailing list
http://www.openwall.com/lists/oss-security/2020/08/08/8 third party advisory mailing list
http://www.openwall.com/lists/oss-security/2020/08/08/9 third party advisory mailing list
http://www.openwall.com/lists/oss-security/2020/08/10/5 mailing list vendor advisory
https://lists.apache.org/thread.html/r5debe8f82728a00a4a68bc904dd6c35423bdfc8d601cfb4579f38bf1%40%3Cdev.httpd.apache.org%3E mailing list
https://lists.apache.org/thread.html/r623de9b2b2433a87f3f3a15900419fc9c00c77b26936dfea4060f672%40%3Cdev.httpd.apache.org%3E mailing list
http://www.openwall.com/lists/oss-security/2020/08/17/2 third party advisory mailing list
https://usn.ubuntu.com/4458-1/ third party advisory vendor advisory
http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00068.html mailing list third party advisory vendor advisory
http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00071.html mailing list third party advisory vendor advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HYVYE2ZERFXDV6RMKK3I5SDSDQLPSEIQ/ vendor advisory
https://www.debian.org/security/2020/dsa-4757 third party advisory vendor advisory
https://lists.debian.org/debian-lts-announce/2020/09/msg00001.html third party advisory mailing list
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/A2RN46PRBJE7E7OPD4YZX5SVWV5QKGV5/ vendor advisory
https://www.oracle.com/security-alerts/cpuoct2020.html third party advisory
https://security.netapp.com/advisory/ntap-20200814-0005/ third party advisory
http://packetstormsecurity.com/files/159009/Apache2-mod_proxy_uwsgi-Incorrect-Request-Handling.html exploit vdb entry third party advisory
https://www.oracle.com/security-alerts/cpujan2021.html third party advisory
https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E mailing list
https://lists.apache.org/thread.html/r06f0d87ebb6d59ed8379633f36f72f5b1f79cadfda72ede0830b42cf%40%3Ccvs.httpd.apache.org%3E mailing list
https://lists.apache.org/thread.html/r09bb998baee74a2c316446bd1a41ae7f8d7049d09d9ff991471e8775%40%3Ccvs.httpd.apache.org%3E mailing list
https://lists.apache.org/thread.html/rc998b18880df98bafaade071346690c2bc1444adaa1a1ea464b93f0a%40%3Ccvs.httpd.apache.org%3E mailing list
https://lists.apache.org/thread.html/r03ee478b3dda3e381fd6189366fa7af97c980d2f602846eef935277d%40%3Ccvs.httpd.apache.org%3E mailing list
https://lists.apache.org/thread.html/r34753590ae8e3f2b6af689af4fe84269b592f5fda9f3244fd9abbce8%40%3Ccvs.httpd.apache.org%3E mailing list
https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E mailing list
https://lists.apache.org/thread.html/r3c5c3104813c1c5508b55564b66546933079250a46ce50eee90b2e36%40%3Ccvs.httpd.apache.org%3E mailing list
https://lists.apache.org/thread.html/rf71eb428714374a6f9ad68952e23611ec7807b029fd6a1b4f5f732d9%40%3Ccvs.httpd.apache.org%3E mailing list
https://lists.apache.org/thread.html/r2c6083f6a2027914a0f5b54e2a1f4fa98c03f8693b58460911818255%40%3Ccvs.httpd.apache.org%3E mailing list
https://lists.apache.org/thread.html/r76142b8c5119df2178be7c2dba88fde552eedeec37ea993dfce68d1d%40%3Ccvs.httpd.apache.org%3E mailing list

Frequently Asked Questions

What is the severity of CVE-2020-11984?
CVE-2020-11984 has been scored as a critical severity vulnerability.
How to fix CVE-2020-11984?
To fix CVE-2020-11984, make sure you are using an up-to-date version of the affected component(s) by checking the vendor release notes. As for now, there are no other specific guidelines available.
Is CVE-2020-11984 being actively exploited in the wild?
It is possible that CVE-2020-11984 is being exploited or will be exploited in a near future based on public information. According to its EPSS score, there is a ~50% probability that this vulnerability will be exploited by malicious actors in the next 30 days.
What software or system is affected by CVE-2020-11984?
CVE-2020-11984 affects n/a Apache HTTP Server.
This platform uses data from the NIST NVD, MITRE CVE, MITRE CWE, First.org and CISA KEV but is not endorsed or certified by these entities. CVE is a registred trademark of the MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. CWE is a registred trademark of the MITRE Corporation and the authoritative source of CWE content is MITRE's CWE web site.
© 2025 Under My Watch. All Rights Reserved.