Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2021-3856

Опубликовано: 14 окт. 2021
Источник: oracle-oval
Платформа: Oracle Linux 7

Описание

ELSA-2021-3856: httpd security update (IMPORTANT)

[2.4.6-97.0.1.1]

  • replace index.html with Oracle's index page oracle_index.html

[2.4.6-97.1]

  • Resolves: #2011729 - CVE-2021-40438 httpd: mod_proxy: SSRF via a crafted request uri-path containing 'unix:'

Обновленные пакеты

Oracle Linux 7

Oracle Linux aarch64

httpd

2.4.6-97.0.1.el7_9.1

httpd-devel

2.4.6-97.0.1.el7_9.1

httpd-manual

2.4.6-97.0.1.el7_9.1

httpd-tools

2.4.6-97.0.1.el7_9.1

mod_ldap

2.4.6-97.0.1.el7_9.1

mod_proxy_html

2.4.6-97.0.1.el7_9.1

mod_session

2.4.6-97.0.1.el7_9.1

mod_ssl

2.4.6-97.0.1.el7_9.1

Oracle Linux x86_64

httpd

2.4.6-97.0.1.el7_9.1

httpd-devel

2.4.6-97.0.1.el7_9.1

httpd-manual

2.4.6-97.0.1.el7_9.1

httpd-tools

2.4.6-97.0.1.el7_9.1

mod_ldap

2.4.6-97.0.1.el7_9.1

mod_proxy_html

2.4.6-97.0.1.el7_9.1

mod_session

2.4.6-97.0.1.el7_9.1

mod_ssl

2.4.6-97.0.1.el7_9.1

Связанные CVE

Связанные уязвимости

CVSS3: 9
ubuntu
почти 4 года назад

A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.

CVSS3: 9
redhat
почти 4 года назад

A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.

CVSS3: 9
nvd
почти 4 года назад

A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.

CVSS3: 9
msrc
больше 3 лет назад

Описание отсутствует

CVSS3: 9
debian
почти 4 года назад

A crafted request uri-path can cause mod_proxy to forward the request ...

Уязвимость ELSA-2021-3856