Skip to main content

Nine vulnerabilities have been patched, including two that could allow information disclosure and three that could lead to remote code execution

Summary

Nine vulnerabilities have been patched, including two that could allow information disclosure and three that could lead to remote code execution

Affected platforms

The following platforms are known to be affected:

Threat details

Introduction

The Apache Software Foundation has released two updates to HTTP Server (sometimes known as 'httpd'), which address nine vulnerabilities. Apache HTTP Server is an open-source cross-platform web server implementation.

Remediation advice

Affected organisations are encouraged to review the release notes for Apache HTTP Server 2.4.60 and Apache HTTP Server 2.4.61 on the Apache HTTP Server 2.4 vulnerabilities webpage and apply any relevant updates.  

Note: Updating to Apache HTTP Server 2.4.61 will remediate all nine vulnerabilities. Organisations are strongly encouraged to update to version 2.4.61.

Definitive source of threat updates

CVE Vulnerabilities

Last edited: 8 July 2024 3:59 pm