RHSA-2022:1915: Moderate: httpd:2.4 security and bug fix update
The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server.Security Fix(es): httpd: Request splitting via HTTP/2 method injection and mod_proxy (CVE-2021-33193) httpd: mod_proxy_uwsgi: out-of-bounds read via a crafted request uri-path (CVE-2021-36160) httpd: possible NULL dereference or SSRF in forward proxy configurations (CVE-2021-44224) httpd: Single zero byte stack overflow in mod_auth_digest (CVE-2020-35452) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Additional Changes:For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.6 Release Notes linked from the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:1915?
The severity of RHSA-2022:1915 is considered important.
How do I fix RHSA-2022:1915?
To fix RHSA-2022:1915, update the httpd package to version 2.4.37-47.module+el8.6.0+14529+083145da.1 or later.
What vulnerabilities are addressed by RHSA-2022:1915?
RHSA-2022:1915 addresses vulnerabilities such as CVE-2021-33193 related to request splitting via HTTP/2 method injection.
Which packages are affected by RHSA-2022:1915?
RHSA-2022:1915 affects several packages including httpd, httpd-filesystem, and httpd-tools among others.
Is there a workaround for RHSA-2022:1915?
There is no specific workaround for RHSA-2022:1915; upgrading to the fixed version is recommended.