Description
IP address spoofing when proxying using mod_remoteip and mod_rewrite For configurations using proxying with mod_remoteip and certain mod_rewrite rules, an attacker could spoof their IP address for logging and PHP scripts. Note this issue was fixed in Apache HTTP Server 2.4.24 but was retrospectively allocated a low severity CVE in 2020.
Remediation
References
Related Vulnerabilities
WordPress Plugin Delightful Downloads Directory Traversal (1.6.6)
WordPress Plugin One Click SSL Cross-Site Request Forgery (1.4.6)
Open Resty Uncontrolled Resource Consumption Vulnerability (CVE-2023-44487)
Drupal Reliance on Cookies without Validation and Integrity Checking Vulnerability (CVE-2022-29248)