Please update httpd to 2.4.49 (security release)

Resolves high-severity “mod_proxy SSRF” (CVE-2021-40438), “Request splitting via HTTP/2 method injection and mod_proxy” (CVE-2021-33193), and “NULL pointer dereference” (CVE-2021-34798) vulnerabilities.
This commit is contained in:
Stephen L.B 2021-09-21 03:21:41 +00:00 committed by GitHub
parent e99b0519a8
commit f06d2d5150
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
1 changed files with 2 additions and 2 deletions

View File

@ -18,8 +18,8 @@ RUN set -eux; \
; \
rm -rf /var/lib/apt/lists/*
ENV HTTPD_VERSION 2.4.48
ENV HTTPD_SHA256 1bc826e7b2e88108c7e4bf43c026636f77a41d849cfb667aa7b5c0b86dbf966c
ENV HTTPD_VERSION 2.4.49
ENV HTTPD_SHA256 65b965d6890ea90d9706595e4b7b9365b5060bec8ea723449480b4769974133b
# https://httpd.apache.org/security/vulnerabilities_24.html
ENV HTTPD_PATCHES=""