{"cves":["CVE-2024-38475","CVE-2024-38477","CVE-2024-38473","CVE-2024-39573","CVE-2024-38474"],"cvss":0.0,"database_specific":{"severity":"IMPORTANT"},"description":"httpd\n[2.4.37-65.0.1.1]\n- Replace index.html with Oracle's index page oracle_index.html\n\n[2.4.37-65.1]\n- Resolves: RHEL-45812 - httpd:2.4/httpd: Substitution encoding issue\n  in mod_rewrite (CVE-2024-38474)\n- Resolves: RHEL-45785 - httpd:2.4/httpd: Encoding problem in\n  mod_proxy (CVE-2024-38473)\n- Resolves: RHEL-45777 - httpd:2.4/httpd: Improper escaping of output\n  in mod_rewrite (CVE-2024-38475)\n- Resolves: RHEL-45758 - httpd:2.4/httpd: null pointer dereference\n  in mod_proxy (CVE-2024-38477)\n- Resolves: RHEL-45743 - httpd:2.4/httpd: Potential SSRF\n  in mod_rewrite (CVE-2024-39573)\n\nmod_http2\nmod_md","id":"ELSA-2024-4720","ovalId":"oval:com.oracle.elsa:def:20244720","source":"oracle_linux","title":"ELSA-2024-4720:  httpd:2.4 security update (IMPORTANT)","url":"https://linux.oracle.com/errata/ELSA-2024-4720.html"}