RHSA-2024:4504: Moderate: httpd security update
Moderate: httpd security update
Other sources
The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server.Security Fix(es): httpd: modproxyuwsgi HTTP response splitting (CVE-2023-27522) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:4504?
The severity of RHSA-2024:4504 is classified as moderate.
What vulnerabilities are addressed in RHSA-2024:4504?
RHSA-2024:4504 addresses HTTP response splitting in mod_proxy_uwsgi as detailed in CVE-2023-27522.
How do I fix RHSA-2024:4504?
To fix RHSA-2024:4504, update the httpd package to version 2.4.53-11.el9_2.6 or higher.
Which products are affected by RHSA-2024:4504?
Affected products include various versions of Red Hat Enterprise Linux for x86_64, Power LE, and ARM 64.
Is my system vulnerable if I use Red Hat Enterprise Linux and have not updated to the latest package for RHSA-2024:4504?
Yes, systems running affected versions without the latest httpd package updates are at risk for the vulnerability described in RHSA-2024:4504.