Vulnerability record · CVE-2011-4317 · published 30 November 2011
CVE-2011-4317: Apache mod_proxy reverse proxy bypass via malformed URI
Apache · Http Server
Apache HTTP Server mod_proxy, when the Revision 1179239 patch is applied, mishandles RewriteRule and ProxyPassMatch pattern matches for reverse proxy configuration. A malformed URI containing @ and : characters in invalid positions lets a remote client reach intranet servers through the proxy. It is an incomplete fix for CVE-2011-3368, so systems patched only for that earlier issue remain exposed.
Description
The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21, when the Revision 1179239 patch is in place, does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern matches for configuration of a reverse proxy, which allows remote attackers to send requests to intranet servers via a malformed URI containing an @ (at sign) character and a : (colon) character in invalid positions. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-3368.
AV:N/AC:M/Au:N/C:N/I:P/A:N
Automated analysis
medium priorityCVSS 2.0 rates it 4.3 (MEDIUM) with integrity-only impact, but EPSS is high and exploit-tagged references exist, so it warrants prompt patching.
What it is
Apache HTTP Server mod_proxy, when the Revision 1179239 patch is applied, mishandles RewriteRule and ProxyPassMatch pattern matches for reverse proxy configuration. A malformed URI containing @ and : characters in invalid positions lets a remote client reach intranet servers through the proxy. It is an incomplete fix for CVE-2011-3368, so systems patched only for that earlier issue remain exposed.
Impact
An attacker can bypass intended proxy access restrictions and route requests to internal or intranet servers that should not be reachable from outside. The CVSS vector shows integrity impact only (I:P) with no confidentiality or availability impact.
Attack surface
Reached remotely over the network via HTTP requests to a reverse proxy configured with RewriteRule or ProxyPassMatch. No authentication is required (Au:N); the vector does not indicate user interaction.
Exploitation
Not listed in CISA KEV. EPSS 30-day probability is 0.59603 (99.083 percentile), and two references carry an Exploit tag, indicating public exploit discussion exists.
What to do
- Apply the vendor fix for CVE-2011-4317; do not rely on the earlier CVE-2011-3368 patch alone.
- Upgrade to a supported Apache HTTP Server release, since 1.3.x, 2.0.x and 2.2.x are long end-of-life.
- Review RewriteRule and ProxyPassMatch reverse proxy configurations and tighten destination restrictions where possible.
- Restrict proxy egress to required backend hosts so malformed URIs cannot reach unintended intranet targets.
Detection
- Inspect proxy access logs for request URIs containing @ and : in unusual positions.
- Alert on proxy requests whose resolved backend destination differs from the configured target.
- Monitor for scanning or repeated malformed-URI requests against reverse proxy endpoints.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2011-4317 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2011-4317), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.