RHSA-2025:3452LowCVSS 5.9
Red Hat Security Advisory: Red Hat JBoss Core Services Apache HTTP Server 2.4.62 security update
🔗 CVE IDs covered (3)
📋 Description
CVE-2024-5535 — openssl: SSL_select_next_proto buffer overread CVE-2024-24795 — httpd: HTTP Response Splitting in multiple modules CVE-2024-36387 — mod_http2: DoS by null pointer in websocket over HTTP/2
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2025:3452
- externalhttps://access.redhat.com/security/updates/classification/#low
- externalhttps://docs.redhat.com/en/documentation/red_hat_jboss_core_services/2.4.62/html/red_hat_jboss_core_services_apache_http_server_2.4.62_release_notes/index
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2273499
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2294581
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2295006
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_3452.json