{
  "cves": [
    "CVE-2024-38475",
    "CVE-2024-38477",
    "CVE-2024-38473",
    "CVE-2024-39573",
    "CVE-2024-38474"
  ],
  "cvss": 0.0,
  "database_specific": {
    "severity": "IMPORTANT"
  },
  "description": "httpd\n[2.4.37-65.0.1.1]\n- Replace index.html with Oracle's index page oracle_index.html\n\n[2.4.37-65.1]\n- Resolves: RHEL-45812 - httpd:2.4/httpd: Substitution encoding issue\n  in mod_rewrite (CVE-2024-38474)\n- Resolves: RHEL-45785 - httpd:2.4/httpd: Encoding problem in\n  mod_proxy (CVE-2024-38473)\n- Resolves: RHEL-45777 - httpd:2.4/httpd: Improper escaping of output\n  in mod_rewrite (CVE-2024-38475)\n- Resolves: RHEL-45758 - httpd:2.4/httpd: null pointer dereference\n  in mod_proxy (CVE-2024-38477)\n- Resolves: RHEL-45743 - httpd:2.4/httpd: Potential SSRF\n  in mod_rewrite (CVE-2024-39573)\n\nmod_http2\nmod_md",
  "id": "ELSA-2024-4720",
  "ovalId": "oval:com.oracle.elsa:def:20244720",
  "source": "oracle_linux",
  "title": "ELSA-2024-4720:  httpd:2.4 security update (IMPORTANT)",
  "url": "https://linux.oracle.com/errata/ELSA-2024-4720.html"
}