CVE-2020-11985: Apache HTTP Server
Medium severity, CVSS 5.3. EPSS: 7.1% chance of exploitation in the next 30 days.
IP address spoofing when proxying using mod_remoteip and mod_rewrite For configurations using proxying with mod_remoteip and certain mod_rewrite rules, an attacker could spoof their IP address for logging and PHP scripts. Note this issue was fixed in Apache HTTP Server 2.4.24 but was retrospectively allocated a low severity CVE in 2020.
Affected products
- Apache HTTP Server: from 2.4.1, up to and including 2.4.23
Published 2020-08-07. Last modified 2026-06-17.