Lucene search
Basic search
Lucene search
Search by product
Subscribe
K
Start 30-day trial
Database
Vendors
Products
Years
CVSS
Scanner
Agent Scanning
API Scanning
Manual Audit
Perimeter Scanner
Scanning
Projects
Email
Webhook
Plugins
Resources
Documents
Blog
Glossary
FAQ
Pricing
Contacts
About Us
Partners
Branding Guideline
SIGN IN
OracleLinux
ELSA-2021-4257
History
Nov 16, 2021 - 12:00 a.m.
Vulners
/
Oraclelinux
/
httpd:2.4 security, bug fix, and enhancement update
httpd:2.4 security, bug fix, and enhancement update
2021-11-16
00:00:00
linux.oracle.com
37
apache http server 2.4
bug fixes
security enhancements
oracle product
tls records
ssl certificates
samesite cookies
http/https
xml
virtual hosts
acme server
EPSS
0.082
Percentile
94.5%
JSON
httpd
[2.4.37-41.0.1]
Add checks on the configured UDS path [Orabug: 33412270][CVE-2021-40438]
Set vstring per ORACLE_SUPPORT_PRODUCT [Orabug: 29892262]
Replace index.html with Oracles index page oracle_index.html
[2.4.37-41]
Resolves: #1680111 - httpd sends reply to HTTPS GET using two TLS records
Resolves: #1905613 - mod_ssl does not like valid certificate chain
Resolves: #1935742 - [RFE] backport samesite/httponly/secure flags for
usertrack
Resolves: #1972500 - CVE-2021-30641 httpd:2.4/httpd: MergeSlashes regression
Resolves: #1968307 - CVE-2021-26690 httpd:2.4/httpd: mod_session NULL pointer
dereference in parser
Resolves: #1934741 - Apache trademark update - new logo
[2.4.37-40]
Resolves: #1952557 - mod_proxy_wstunnel.html is a malformed XML
Resolves: #1937334 - SSLProtocol with based virtual hosts
mod_http2
[1.15.7-3]
Resolves: #1869077 - CVE-2020-11993 httpd:2.4/mod_http2: httpd:
mod_http2 concurrent pool usage
mod_md
[1:2.0.8-8]
Resolves: #1832844 - mod_md does not work with ACME server that does not
provide keyChange or revokeCert resources
Affected Package
OS
Version
Architecture
Package
Version
Filename
oracle linux
8
src
httpd
< 2.4.37-41.0.1.module
httpd-2.4.37-41.0.1.module+el8.5.0+20323+c8e0c271.src.rpm
oracle linux
8
src
mod_http2
< 1.15.7-3.module
mod_http2-1.15.7-3.module+el8.4.0+20024+b87b2deb.src.rpm
oracle linux
8
src
mod_md
< 2.0.8-8.module
mod_md-2.0.8-8.module+el8.3.0+7816+49791cfd.src.rpm
oracle linux
8
aarch64
httpd
< 2.4.37-41.0.1.module
httpd-2.4.37-41.0.1.module+el8.5.0+20323+c8e0c271.aarch64.rpm
oracle linux
8
aarch64
httpd-devel
< 2.4.37-41.0.1.module
httpd-devel-2.4.37-41.0.1.module+el8.5.0+20323+c8e0c271.aarch64.rpm
oracle linux
8
noarch
httpd-filesystem
< 2.4.37-41.0.1.module
httpd-filesystem-2.4.37-41.0.1.module+el8.5.0+20323+c8e0c271.noarch.rpm
oracle linux
8
noarch
httpd-manual
< 2.4.37-41.0.1.module
httpd-manual-2.4.37-41.0.1.module+el8.5.0+20323+c8e0c271.noarch.rpm
oracle linux
8
aarch64
httpd-tools
< 2.4.37-41.0.1.module
httpd-tools-2.4.37-41.0.1.module+el8.5.0+20323+c8e0c271.aarch64.rpm
oracle linux
8
aarch64
mod_http2
< 1.15.7-3.module
mod_http2-1.15.7-3.module+el8.4.0+20024+b87b2deb.aarch64.rpm
oracle linux
8
aarch64
mod_ldap
< 2.4.37-41.0.1.module
mod_ldap-2.4.37-41.0.1.module+el8.5.0+20323+c8e0c271.aarch64.rpm
Rows per page:
10
1-10 of 28
1
Related
osv 10
rocky 1
redhat 3
nessus 48
almalinux 1
ubuntu 2
openvas 32
ibm 27
oraclelinux 2
alpinelinux 2
httpd 2
cbl_mariner 4
cvelist 2
f5 2
veracode 2
redhatcve 2
debian 2
nvd 2
cve 2
debiancve 2
ubuntucve 2
cnvd 1
prion 2
photon 5
suse 2
gentoo 1
mageia 1
slackware 1
amazon 3
kaspersky 1
freebsd 1
fedora 2
rosalinux 1
oracle 3
osv
osv
10
Moderate: httpd:2.4 security, bug fix, and enhancement update
2021-11-09 08:52:38
Moderate: httpd:2.4 security, bug fix, and enhancement update
2021-11-09 08:52:38
apache2 vulnerabilities
2021-06-21 15:25:05
rocky
rocky
httpd:2.4 security, bug fix, and enhancement update
2021-11-09 08:52:38
redhat
redhat
(RHSA-2021:4257) Moderate: httpd:2.4 security, bug fix, and enhancement update
2021-11-09 08:52:38
(RHSA-2021:4614) Moderate: Red Hat JBoss Core Services Apache HTTP Server 2.4.37 SP10 security update
2021-11-10 17:10:19
(RHSA-2021:4613) Moderate: Red Hat JBoss Core Services Apache HTTP Server 2.4.37 SP10 security update
2021-11-10 17:09:50
nessus
nessus
48
Oracle Linux 8 : httpd:2.4 (ELSA-2021-4257)
2021-11-17 00:00:00
Rocky Linux 8 : httpd:2.4 (RLSA-2021:4257)
2023-11-06 00:00:00
AlmaLinux 8 : httpd:2.4 (ALSA-2021:4257)
2022-03-12 00:00:00
almalinux
almalinux
Moderate: httpd:2.4 security, bug fix, and enhancement update
2021-11-09 08:52:38
ubuntu
ubuntu
Apache HTTP Server vulnerabilities
2021-06-21 00:00:00
Apache HTTP Server vulnerabilities
2021-06-21 00:00:00
openvas
openvas
32
Huawei EulerOS: Security Advisory for httpd (EulerOS-SA-2021-2779)
2021-11-17 00:00:00
Ubuntu: Security Advisory (USN-4994-2)
2022-08-26 00:00:00
Huawei EulerOS: Security Advisory for httpd (EulerOS-SA-2021-2529)
2021-09-28 00:00:00
ibm
ibm
27
Security Bulletin: Multiple security vulnerabilities have been identified in IBM HTTP Server shipped with IBM Rational ClearCase (CVE-2020-13938, CVE-2021-30641, CVE-2021-26690, CVE-2021-26691)
2021-09-16 06:03:38
Security Bulletin: Vulnerability identified in WebSphere Application Server affects Cloud Pak System (CVE-2021-30641)
2021-07-14 22:33:16
Security Bulletin: Multiple Vulnerabilities have been identified in WebSphere Application Server shipped with WebSphere Remote Server
2021-06-28 18:00:22
oraclelinux
oraclelinux
httpd security update
2021-11-04 00:00:00
httpd:2.4 security update
2021-11-11 00:00:00
alpinelinux
alpinelinux
CVE-2021-26690
2021-06-10 07:15:07
CVE-2021-30641
2021-06-10 07:15:07
httpd
httpd
Apache Httpd < 2.4.48 : Unexpected URL matching with 'MergeSlashes OFF'
2021-04-14 00:00:00
Apache Httpd < 2.4.48 : mod_session NULL pointer dereference
2021-02-08 00:00:00
cbl_mariner
cbl_mariner
4
CVE-2021-30641 affecting package httpd 2.4.46-6
2021-07-08 21:56:40
CVE-2021-26690 affecting package httpd for versions less than 2.4.46-10
2022-04-09 06:51:57
CVE-2021-30641 affecting package httpd for versions less than 2.4.46-10
2022-04-09 06:51:57
cvelist
cvelist
CVE-2021-30641 Unexpected URL matching with 'MergeSlashes OFF'
2021-06-10 07:10:24
CVE-2021-26690 mod_session NULL pointer dereference
2021-06-10 07:10:22
f5
f5
K41320158 : Apache vulnerability CVE-2021-26690
2022-05-10 00:00:00
K13815051 : Apache vulnerability CVE-2021-30641
2021-07-09 00:00:00
veracode
veracode
Denial Of Service(DoS)
2021-06-13 03:24:50
Denial Of Service(DoS)
2021-06-13 10:29:41
redhatcve
redhatcve
CVE-2021-26690
2021-06-07 06:12:59
CVE-2021-30641
2021-06-08 03:49:52
debian
debian
[SECURITY] [DSA 4937-1] apache2 security update
2021-07-08 17:14:14
[SECURITY] [DLA 2706-1] apache2 security update
2021-07-09 08:50:21
nvd
nvd
CVE-2021-30641
2021-06-10 07:15:07
CVE-2021-26690
2021-06-10 07:15:07
cve
cve
CVE-2021-30641
2021-06-10 07:15:07
CVE-2021-26690
2021-06-10 07:15:07
debiancve
debiancve
CVE-2021-26690
2021-06-10 07:15:07
CVE-2021-30641
2021-06-10 07:15:07
ubuntucve
ubuntucve
CVE-2021-26690
2021-06-10 00:00:00
CVE-2021-30641
2021-06-10 00:00:00
cnvd
cnvd
Apache HTTP Server Code Issue Vulnerability (CNVD-2022-13199)
2021-06-11 00:00:00
prion
prion
Null pointer dereference
2021-06-10 07:15:00
Code injection
2021-06-10 07:15:00
photon
photon
5
Home Download Photon OS User Documentation FAQ Security Advisories Related Information Lightwave - PHSA-2021-2.0-0365
2021-06-30 00:00:00
Home Download Photon OS User Documentation FAQ Security Advisories Related Information Lightwave - PHSA-2021-1.0-0409
2021-07-01 00:00:00
Important Photon OS Security Update - PHSA-2021-0257
2021-06-22 00:00:00
suse
suse
Security update for apache2 (important)
2021-07-10 00:00:00
Security update for apache2 (important)
2021-06-24 00:00:00
gentoo
gentoo
Apache: Multiple vulnerabilities
2021-07-17 00:00:00
mageia
mageia
Updated apache packages fix security vulnerabilities
2021-06-16 23:22:25
slackware
slackware
[slackware-security] httpd
2021-06-07 19:07:12
amazon
amazon
Medium: httpd
2021-07-01 00:59:00
Medium: httpd24
2021-07-08 18:38:00
Important: httpd
2021-06-16 20:37:00
kaspersky
kaspersky
KLA12369 Multiple vulnerabilities in Apache HTTP Server
2021-06-01 00:00:00
freebsd
freebsd
Apache httpd -- Multiple vulnerabilities
2021-06-09 00:00:00
fedora
fedora
[SECURITY] Fedora 34 Update: httpd-2.4.49-1.fc34
2021-09-20 13:58:04
[SECURITY] Fedora 35 Update: httpd-2.4.49-1.fc35
2021-09-24 20:56:12
rosalinux
rosalinux
Advisory ROSA-SA-2023-2159
2023-04-25 11:49:15
oracle
oracle
Oracle Critical Patch Update Advisory - October 2021
2021-10-19 00:00:00
Oracle Critical Patch Update Advisory - January 2023
2023-01-17 00:00:00
Oracle Critical Patch Update Advisory - October 2022
2022-10-18 00:00:00
EPSS
0.082
Percentile
94.5%
JSON
Related for ELSA-2021-4257
osv
10
rocky
1
redhat
3
nessus
48
almalinux
1
ubuntu
2
openvas
32
ibm
27
oraclelinux
2
alpinelinux
2
httpd
2
cbl_mariner
4
cvelist
2
f5
2
veracode
2
redhatcve
2
debian
2
nvd
2
cve
2
debiancve
2
ubuntucve
2
cnvd
1
prion
2
photon
5
suse
2
gentoo
1
mageia
1
slackware
1
amazon
3
kaspersky
1
freebsd
1
fedora
2
rosalinux
1
oracle
3