Release of the Apache 2.4.54 HTTP server with vulnerability fixes
The release of HTTP server Apache 2.4.53 has been announced, featuring 19 changes and fixing 8 vulnerabilities: CVE-2022-31813 — a vulnerability in mod_proxy that allows blocking the transmission of X-Forwarded-* headers containing information about the IP address from which the original request came. This issue can be exploited to bypass IP address access restrictions. CVE-2022-30556 — a vulnerability in mod_lua that allows access to data beyond […]
