Nine vulnerabilities have been patched, including two that could allow information disclosure and three that could lead to remote code execution
Summary
Nine vulnerabilities have been patched, including two that could allow information disclosure and three that could lead to remote code execution
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
The Apache Software Foundation has released two updates to HTTP Server (sometimes known as 'httpd'), which address nine vulnerabilities. Apache HTTP Server is an open-source cross-platform web server implementation.
Remediation advice
Affected organisations are encouraged to review the release notes for Apache HTTP Server 2.4.60 and Apache HTTP Server 2.4.61 on the Apache HTTP Server 2.4 vulnerabilities webpage and apply any relevant updates.
Note: Updating to Apache HTTP Server 2.4.61 will remediate all nine vulnerabilities. Organisations are strongly encouraged to update to version 2.4.61.
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 8 July 2024 3:59 pm