RHSA-2021:3836: Important: httpd:2.4 security update
The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server.Security Fix(es): httpd: modproxy: SSRF via a crafted request uri-path containing "unix:" (CVE-2021-40438) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/httpdto a version that resolves this vulnerability.Fixed in 2.4.37-21.module+el8.2.0+12904+53ee7aba.1 - Upgrade
Upgrade
redhat/httpd-debuginfoto a version that resolves this vulnerability.Fixed in 2.4.37-21.module+el8.2.0+12904+53ee7aba.1 - Upgrade
Upgrade
redhat/httpd-debugsourceto a version that resolves this vulnerability.Fixed in 2.4.37-21.module+el8.2.0+12904+53ee7aba.1 - Upgrade
Upgrade
redhat/httpd-develto a version that resolves this vulnerability.Fixed in 2.4.37-21.module+el8.2.0+12904+53ee7aba.1 - Upgrade
Upgrade
redhat/httpd-filesystemto a version that resolves this vulnerability.Fixed in 2.4.37-21.module+el8.2.0+12904+53ee7aba.1 - Upgrade
Upgrade
redhat/httpd-manualto a version that resolves this vulnerability.Fixed in 2.4.37-21.module+el8.2.0+12904+53ee7aba.1 - Upgrade
Upgrade
redhat/httpd-toolsto a version that resolves this vulnerability.Fixed in 2.4.37-21.module+el8.2.0+12904+53ee7aba.1 - Upgrade
Upgrade
redhat/httpd-tools-debuginfoto a version that resolves this vulnerability.Fixed in 2.4.37-21.module+el8.2.0+12904+53ee7aba.1 - Upgrade
Upgrade
redhat/httpdto a version that resolves this vulnerability.Fixed in 2.4.37-21.module+el8.2.0+12904+53ee7aba.1.aa - Upgrade
Upgrade
redhat/httpd-debuginfoto a version that resolves this vulnerability.Fixed in 2.4.37-21.module+el8.2.0+12904+53ee7aba.1.aa - Upgrade
Upgrade
redhat/httpd-debugsourceto a version that resolves this vulnerability.Fixed in 2.4.37-21.module+el8.2.0+12904+53ee7aba.1.aa - Upgrade
Upgrade
redhat/httpd-develto a version that resolves this vulnerability.Fixed in 2.4.37-21.module+el8.2.0+12904+53ee7aba.1.aa - Upgrade
Upgrade
redhat/httpd-toolsto a version that resolves this vulnerability.Fixed in 2.4.37-21.module+el8.2.0+12904+53ee7aba.1.aa - Upgrade
Upgrade
redhat/httpd-tools-debuginfoto a version that resolves this vulnerability.Fixed in 2.4.37-21.module+el8.2.0+12904+53ee7aba.1.aa - Upgrade
Upgrade
httpdto a version that resolves this vulnerability.Fixed in 2.4.37-21.module+el8.2.0+12904+53ee7aba.1 - Upgrade
Upgrade
mod_http2to a version that resolves this vulnerability.Fixed in 1.11.3-3.module+el8.2.0+7758+84b4ca3e.1 - Upgrade
Upgrade
mod_ldapto a version that resolves this vulnerability.Fixed in 2.4.37-21.module+el8.2.0+12904+53ee7aba.1 - Upgrade
Upgrade
mod_mdto a version that resolves this vulnerability.Fixed in 2.0.8-7.module+el8.2.0+5531+7e4d69a2 - Upgrade
Upgrade
mod_proxy_htmlto a version that resolves this vulnerability.Fixed in 2.4.37-21.module+el8.2.0+12904+53ee7aba.1 - Upgrade
Upgrade
mod_sessionto a version that resolves this vulnerability.Fixed in 2.4.37-21.module+el8.2.0+12904+53ee7aba.1 - Upgrade
Upgrade
mod_sslto a version that resolves this vulnerability.Fixed in 2.4.37-21.module+el8.2.0+12904+53ee7aba.1
Event History
Frequently Asked Questions
What is the severity of RHSA-2021:3836?
The severity of RHSA-2021:3836 is classified as important.
How do I fix RHSA-2021:3836?
To fix RHSA-2021:3836, update your httpd package to version 2.4.37-21.module+el8.2.0+12904+53ee7aba.1 or later.
What does CVE-2021-40438 in RHSA-2021:3836 refer to?
CVE-2021-40438 refers to a Server-Side Request Forgery (SSRF) vulnerability in the mod_proxy module of Apache httpd.
Which packages are affected by RHSA-2021:3836?
The affected packages include httpd, httpd-debuginfo, httpd-devel, httpd-tools, and others in the Red Hat Enterprise Linux environment.
Is RHSA-2021:3836 related to a specific version of Apache HTTP Server?
Yes, RHSA-2021:3836 is specifically related to Apache HTTP Server version prior to 2.4.37-21.module+el8.2.0+12904+53ee7aba.1.