Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Oracle Linux 7 ELSA-2021-3856 Critical Httpd SSRF Vulnerability Resolved

oracle
Calendar Grey October 14, 2021
Scroller Oracle
Important patch release for Oracle Linux 7 tackling SSRF vulnerability in apache2. Refer to the advisory for comprehensive information.
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

Summary

[2.4.6-97.0.1.1] - replace index.html with Oracle's index page oracle_index.html [2.4.6-97.1] - Resolves: #2011729 - CVE-2021-40438 httpd: mod_proxy: SSRF via a crafted request uri-path containing "unix:"

SRPMs

https://oss.oracle.com:443/ol7/SRPMS-updates/httpd-2.4.6-97.0.1.el7_9.1.src.rpm

x86_64

httpd-2.4.6-97.0.1.el7_9.1.x86_64.rpm httpd-devel-2.4.6-97.0.1.el7_9.1.x86_64.rpm httpd-manual-2.4.6-97.0.1.el7_9.1.noarch.rpm httpd-tools-2.4.6-97.0.1.el7_9.1.x86_64.rpm mod_ldap-2.4.6-97.0.1.el7_9.1.x86_64.rpm mod_proxy_html-2.4.6-97.0.1.el7_9.1.x86_64.rpm mod_session-2.4.6-97.0.1.el7_9.1.x86_64.rpm mod_ssl-2.4.6-97.0.1.el7_9.1.x86_64.rpm

aarch64

Severity
critical
Lowest
Low
Medium
High
Critical

Related CVEs: CVE-2021-40438

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.