{"cves":["CVE-2024-38474","CVE-2024-38473","CVE-2024-38477","CVE-2024-39573","CVE-2024-38475"],"cvss":0.0,"database_specific":{"severity":"IMPORTANT"},"description":"[2.4.57-11.0.1]\n- Replace index.html with Oracle's index page oracle_index.html.\n\n[2.4.57-11]\n- Resolves: RHEL-45792 -  httpd: Encoding problem in\n  mod_proxy (CVE-2024-38473)\n\n[2.4.57-9]\n- Resolves: RHEL-45766 -  httpd: null pointer dereference in\n  mod_proxy (CVE-2024-38477)\n- Resolves: RHEL-45749 - httpd: Potential SSRF in mod_rewrite (CVE-2024-39573)\n- Resolves: RHEL-45818 - httpd: Substitution encoding issue in\n  mod_rewrite (CVE-2024-38474)\n- Resolves: RHEL-45771 - httpd: Improper escaping of output in\n  mod_rewrite (CVE-2024-38475)","id":"ELSA-2024-4726","ovalId":"oval:com.oracle.elsa:def:20244726","source":"oracle_linux","title":"ELSA-2024-4726:  httpd security update (IMPORTANT)","url":"https://linux.oracle.com/errata/ELSA-2024-4726.html"}