Vulnerability record · CVE-2011-3368 · published 5 October 2011
CVE-2011-3368: Apache mod_proxy reverse proxy bypass via malformed URI
Apache · Http Server
Apache HTTP Server mod_proxy mishandles RewriteRule and ProxyPassMatch pattern matching when a request URI begins with an @ character, allowing the reverse proxy to forward requests to unintended intranet servers. This matters because a proxy meant to restrict access to internal systems can be used as a pivot into the internal network.
Description
The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21 does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern matches for configuration of a reverse proxy, which allows remote attackers to send requests to intranet servers via a malformed URI containing an initial @ (at sign) character.
AV:N/AC:L/Au:N/C:P/I:N/A:N
Automated analysis
high priorityThe flaw allows unauthenticated network attackers to bypass reverse proxy restrictions and reach intranet servers, and EPSS is very high with public exploit references, though the CVSS 2.0 score is only 5.0 (medium).
What it is
Apache HTTP Server mod_proxy mishandles RewriteRule and ProxyPassMatch pattern matching when a request URI begins with an @ character, allowing the reverse proxy to forward requests to unintended intranet servers. This matters because a proxy meant to restrict access to internal systems can be used as a pivot into the internal network.
Impact
A remote attacker can cause the proxy to send requests to intranet servers that should not be reachable from outside, exposing internal services and information. The CVSS vector indicates partial confidentiality impact only, with no integrity or availability effect.
Attack surface
Reachable over the network via HTTP requests to a server configured as a reverse proxy using RewriteRule or ProxyPassMatch; no authentication or user interaction is required per the AV:N/AC:L/Au:N vector.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.90734, 99.8th percentile) and public exploit references exist, including an Exploit-DB entry and a reference tagged Exploit.
What to do
- Upgrade Apache HTTP Server to a version containing the fix for CVE-2011-3368 (see the Apache revision 1179239 patch reference and vendor advisories).
- If immediate upgrade is not possible, review and harden RewriteRule and ProxyPassMatch configurations to avoid patterns that can be bypassed by URIs beginning with @.
- Restrict the reverse proxy's ability to reach internal networks using network segmentation and egress filtering.
- Apply vendor patches from your distribution (Red Hat, Debian, openSUSE, Apple, IBM, Mandriva advisories are referenced).
Detection
- Inspect proxy access logs for request URIs beginning with an @ character or containing @ in the path.
- Monitor for anomalous proxy requests to internal IP ranges or hostnames that are not normally served externally.
- Alert on RewriteRule or ProxyPassMatch configuration changes on reverse proxy hosts.
- Correlate proxy logs with internal service logs for unexpected inbound requests originating from the proxy.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2011-3368 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2011-3368), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.