{
  "cves": [
    "CVE-2021-26691",
    "CVE-2021-40438"
  ],
  "cvss": 0.0,
  "database_specific": {
    "severity": "IMPORTANT"
  },
  "description": "httpd\n[2.4.37-39.1.0.1.1]\n- Set vstring per ORACLE_SUPPORT_PRODUCT [Orabug: 29892262]\n- Replace index.html with Oracle's index page oracle_index.html\n\n[2.4.37-39.1]\n- Resolves: #2007234 - CVE-2021-40438 httpd:2.4/httpd: mod_proxy: SSRF via\n  a crafted request uri-path\n- Resolves: #2007646 - CVE-2021-26691 httpd:2.4/httpd: Heap overflow in\n  mod_session",
  "id": "ELSA-2021-3816",
  "ovalId": "oval:com.oracle.elsa:def:20213816",
  "source": "oracle_linux",
  "title": "ELSA-2021-3816:  httpd:2.4 security update (IMPORTANT)",
  "url": "https://linux.oracle.com/errata/ELSA-2021-3816.html"
}