CRITICAL 9.8 Microsoft PoC
CVE-2020-11984
Apache HTTP server 2.4.32 to 2.4.44 mod_proxy_uwsgi info disclosure and possible RCE
Microsoft Security Update 2020-Aug: Apache HTTP server 2.4.32 to 2.4.44 mod_proxy_uwsgi info disclosure and possible RCE
Affected Products
- cm1 httpd 2.4.46-5 on CBL Mariner 1.0
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2020-11984
- https://nvd.nist.gov/vuln/detail/CVE-2020-11984
This critical severity vulnerability with a CVSS score of 9.8 was published on 2020-08-11 via Microsoft. 🚨 A public proof-of-concept exploit is available on GitHub. EPSS score: 90.0% (top 0% of all CVEs by exploitation probability). Affected: cm1 httpd 2.4.46-5 on CBL Mariner 1.0.
Risk Timeline
CVE Disclosed2020-08-11 · 2200 days ago
Public PoC Exploit AvailableWeaponised proof-of-concept code is publicly accessible
Remediation Resources
Official Advisory
msrc.microsoft.com/update-guide/vulnerability/CVE-2020-11984NVD / MITRE
nvd.nist.gov/vuln/detail/CVE-2020-11984Related Vulnerabilities
| CVE | Title | Severity | CVSS |
|---|---|---|---|
| CVE-2021-43267 PoC | An issue was discovered in net/tipc/crypto.c in the Linux kernel before 5.14.16. | CRITICAL | 9.8 |
| CVE-2022-27404 | FreeType commit 1e2eb65048f75c64b68708efed6ce904c31f3b2f was discovered to conta | CRITICAL | 9.8 |
| CVE-2021-43523 | In uClibc and uClibc-ng before 1.0.39 incorrect handling of special characters i | CRITICAL | 9.6 |
| CVE-2023-25725 PoC | HAProxy before 2.7.3 may allow a bypass of access control because HTTP/1 headers | CRITICAL | 9.1 |
| CVE-2021-4206 | A flaw was found in the QXL display device emulation in QEMU. An integer overflo | HIGH | 8.2 |
| CVE-2021-4207 | A flaw was found in the QXL display device emulation in QEMU. A double fetch of | HIGH | 8.2 |
vulnfeed aggregates 9909 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.