Update Info

SUSE-SLE-Module-Packagehub-Subpackages-15-SP5-2024-2624


Security update for apache2


Type: security
Severity: important
Issued: 2024-07-30
Description:
This update for apache2 fixes the following issues:

- CVE-2024-38475: Fixed improper escaping of output in mod_rewrite (bsc#1227268)
- CVE-2024-38476: Fixed server may use exploitable/malicious backend application output to run local handlers via internal redirect (bsc#1227269)
- CVE-2024-38477: Fixed null pointer dereference in mod_proxy (bsc#1227270)
- CVE-2024-39573: Fixed potential SSRF in mod_rewrite (bsc#1227271)


              

Packages


  • apache2-2.4.51-150400.6.29.1