{
  "cves": [
    "CVE-2024-38474",
    "CVE-2024-38473",
    "CVE-2024-38477",
    "CVE-2024-39573",
    "CVE-2024-38475"
  ],
  "cvss": 0.0,
  "database_specific": {
    "severity": "IMPORTANT"
  },
  "description": "[2.4.57-11.0.1]\n- Replace index.html with Oracle's index page oracle_index.html.\n\n[2.4.57-11]\n- Resolves: RHEL-45792 -  httpd: Encoding problem in\n  mod_proxy (CVE-2024-38473)\n\n[2.4.57-9]\n- Resolves: RHEL-45766 -  httpd: null pointer dereference in\n  mod_proxy (CVE-2024-38477)\n- Resolves: RHEL-45749 - httpd: Potential SSRF in mod_rewrite (CVE-2024-39573)\n- Resolves: RHEL-45818 - httpd: Substitution encoding issue in\n  mod_rewrite (CVE-2024-38474)\n- Resolves: RHEL-45771 - httpd: Improper escaping of output in\n  mod_rewrite (CVE-2024-38475)",
  "id": "ELSA-2024-4726",
  "ovalId": "oval:com.oracle.elsa:def:20244726",
  "source": "oracle_linux",
  "title": "ELSA-2024-4726:  httpd security update (IMPORTANT)",
  "url": "https://linux.oracle.com/errata/ELSA-2024-4726.html"
}