RHSA-2022:1915: Moderate: httpd:2.4 security and bug fix update
The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server.Security Fix(es): httpd: Request splitting via HTTP/2 method injection and modproxy (CVE-2021-33193) httpd: modproxyuwsgi: out-of-bounds read via a crafted request uri-path (CVE-2021-36160) httpd: possible NULL dereference or SSRF in forward proxy configurations (CVE-2021-44224) httpd: Single zero byte stack overflow in modauthdigest (CVE-2020-35452) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Additional Changes:For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.6 Release Notes linked from the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/httpdto a version that resolves this vulnerability.Fixed in 2.4.37-47.module+el8.6.0+14529+083145da.1 - Upgrade
Upgrade
redhat/httpd-filesystemto a version that resolves this vulnerability.Fixed in 2.4.37-47.module+el8.6.0+14529+083145da.1 - Upgrade
Upgrade
redhat/httpd-manualto a version that resolves this vulnerability.Fixed in 2.4.37-47.module+el8.6.0+14529+083145da.1 - Upgrade
Upgrade
redhat/httpd-debuginfoto a version that resolves this vulnerability.Fixed in 2.4.37-47.module+el8.6.0+14529+083145da.1 - Upgrade
Upgrade
redhat/httpd-debugsourceto a version that resolves this vulnerability.Fixed in 2.4.37-47.module+el8.6.0+14529+083145da.1 - Upgrade
Upgrade
redhat/httpd-develto a version that resolves this vulnerability.Fixed in 2.4.37-47.module+el8.6.0+14529+083145da.1 - Upgrade
Upgrade
redhat/httpd-toolsto a version that resolves this vulnerability.Fixed in 2.4.37-47.module+el8.6.0+14529+083145da.1 - Upgrade
Upgrade
redhat/httpd-tools-debuginfoto a version that resolves this vulnerability.Fixed in 2.4.37-47.module+el8.6.0+14529+083145da.1 - Upgrade
Upgrade
redhat/httpdto a version that resolves this vulnerability.Fixed in 2.4.37-47.module+el8.6.0+14529+083145da.1.aa - Upgrade
Upgrade
redhat/httpd-debuginfoto a version that resolves this vulnerability.Fixed in 2.4.37-47.module+el8.6.0+14529+083145da.1.aa - Upgrade
Upgrade
redhat/httpd-debugsourceto a version that resolves this vulnerability.Fixed in 2.4.37-47.module+el8.6.0+14529+083145da.1.aa - Upgrade
Upgrade
redhat/httpd-develto a version that resolves this vulnerability.Fixed in 2.4.37-47.module+el8.6.0+14529+083145da.1.aa - Upgrade
Upgrade
redhat/httpd-toolsto a version that resolves this vulnerability.Fixed in 2.4.37-47.module+el8.6.0+14529+083145da.1.aa - Upgrade
Upgrade
redhat/httpd-tools-debuginfoto a version that resolves this vulnerability.Fixed in 2.4.37-47.module+el8.6.0+14529+083145da.1.aa - Upgrade
Upgrade
httpdto a version that resolves this vulnerability.Patch Moderate: httpd:2.4 security and bug fix update - Upgrade
Upgrade
httpdto a version that resolves this vulnerability.Patch httpd: Request splitting via HTTP/2 method injection and mod_proxy (CVE-2021-33193) - Upgrade
Upgrade
httpdto a version that resolves this vulnerability.Patch httpd: Single zero byte stack overflow in mod_auth_digest (CVE-2020-35452) - Upgrade
Upgrade
httpdto a version that resolves this vulnerability.Patch httpd: mod_proxy_uwsgi: out-of-bounds read via a crafted request uri-path (CVE-2021-36160) - Upgrade
Upgrade
httpdto a version that resolves this vulnerability.Patch httpd: possible NULL dereference or SSRF in forward proxy configurations (CVE-2021-44224) - Operational
After installing the updated httpd packages, ensure the httpd daemon restarts automatically (as stated in the advisory text).
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:1915?
The severity of RHSA-2022:1915 is considered important.
How do I fix RHSA-2022:1915?
To fix RHSA-2022:1915, update the httpd package to version 2.4.37-47.module+el8.6.0+14529+083145da.1 or later.
What vulnerabilities are addressed by RHSA-2022:1915?
RHSA-2022:1915 addresses vulnerabilities such as CVE-2021-33193 related to request splitting via HTTP/2 method injection.
Which packages are affected by RHSA-2022:1915?
RHSA-2022:1915 affects several packages including httpd, httpd-filesystem, and httpd-tools among others.
Is there a workaround for RHSA-2022:1915?
There is no specific workaround for RHSA-2022:1915; upgrading to the fixed version is recommended.