Alibaba Cloud Linux 2.1903 Security Advisory: ALINUX2-SA-2024:0037

Issued: 2024-11-20
Updated: 2024-11-20

Summary

httpd security update

Severity

Important

Description

Package updates are available for Alibaba Cloud Linux 2.1903 that fix the following vulnerabilities:

CVE-2024-38476:
Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend applications whose response headers are malicious or exploitable.
Users are recommended to upgrade to version 2.4.60, which fixes this issue.

References

Updated Packages