peter bassill · operator
$ cve CVE-2020-11984 JSON

CVE-2020-11984

9.8
CRITICAL · CVSS 3.1 · EPSS 90% (pctl 100)

Patch early

EPSS 90% — above the 10% action threshold.

Description

Apache HTTP server 2.4.32 to 2.4.44 mod_proxy_uwsgi info disclosure and possible RCE

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS90.04% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-120
On CISA KEVno
Public exploitnone known
Published2020-08-07
Last modified2026-06-17

Affected (13)

VendorProduct
apachehttp server
canonicalubuntu linux
debiandebian linux
fedoraprojectfedora
netappclustered data ontap
opensuseleap
oraclecommunications element manager
oraclecommunications session report manager
oraclecommunications session route manager
oracleenterprise manager ops center
oraclehyperion infrastructure technology
oracleinstantis enterprisetrack
oraclezfs storage appliance kit

References

→ the Explorer  ·  watch your stack  ·  NVD