Every applicability statement published about this vulnerability, kept as each source wrote it rather than merged into one verdict. Where sources disagree, both positions are shown.
A statement that names no version covers the whole product, which is not the same as your version falling inside a range. Orderings marked best effort come from schemes with no published comparison algorithm; exact ones follow a published specification.
Precedence decides which claim wins when two sources describe the same product over the same version range. It is a property of the source, not of the claim, and changing it re-ranks the data without re-reading a single document.
| Product | Status | Versions | Remediation | Source | |
|---|---|---|---|---|---|
| red_hat_enterprise_linux_8:httpd::httpd:2.4 httpd (httpd:2.4) as a component of Red Hat Enterprise Linux 8 | not affected vulnerable code not present | httpd::httpd:2.4 | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_6:httpd httpd as a component of Red Hat Enterprise Linux 6 | not affected vulnerable code not present | no version stated vendor label: httpd | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_7:httpd httpd as a component of Red Hat Enterprise Linux 7 | not affected vulnerable code not present | no version stated vendor label: httpd | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_9:httpd httpd as a component of Red Hat Enterprise Linux 9 | not affected vulnerable code not present | no version stated vendor label: httpd | not applicable | csaf_redhat | |
| red_hat_jboss_enterprise_application_platform_6:httpd httpd as a component of Red Hat JBoss Enterprise Application Platform 6 | not affected vulnerable code not present | no version stated vendor label: httpd | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_9:httpd-core httpd-core as a component of Red Hat Enterprise Linux 9 | not affected vulnerable code not present | no version stated vendor label: httpd-core | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_8:httpd-devel::httpd:2.4 httpd-devel (httpd:2.4) as a component of Red Hat Enterprise Linux 8 | not affected vulnerable code not present | httpd-devel::httpd:2.4 | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_6:httpd-devel httpd-devel as a component of Red Hat Enterprise Linux 6 | not affected vulnerable code not present | no version stated vendor label: httpd-devel | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_7:httpd-devel httpd-devel as a component of Red Hat Enterprise Linux 7 | not affected vulnerable code not present | no version stated vendor label: httpd-devel | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_9:httpd-devel httpd-devel as a component of Red Hat Enterprise Linux 9 | not affected vulnerable code not present | no version stated vendor label: httpd-devel | not applicable | csaf_redhat | |
| red_hat_jboss_enterprise_application_platform_6:httpd-devel httpd-devel as a component of Red Hat JBoss Enterprise Application Platform 6 | not affected vulnerable code not present | no version stated vendor label: httpd-devel | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_8:httpd-filesystem::httpd:2.4 httpd-filesystem (httpd:2.4) as a component of Red Hat Enterprise Linux 8 | not affected vulnerable code not present | httpd-filesystem::httpd:2.4 | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_9:httpd-filesystem httpd-filesystem as a component of Red Hat Enterprise Linux 9 | not affected vulnerable code not present | no version stated vendor label: httpd-filesystem | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_8:httpd-manual::httpd:2.4 httpd-manual (httpd:2.4) as a component of Red Hat Enterprise Linux 8 | not affected vulnerable code not present | httpd-manual::httpd:2.4 | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_6:httpd-manual httpd-manual as a component of Red Hat Enterprise Linux 6 | not affected vulnerable code not present | no version stated vendor label: httpd-manual | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_7:httpd-manual httpd-manual as a component of Red Hat Enterprise Linux 7 | not affected vulnerable code not present | no version stated vendor label: httpd-manual | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_9:httpd-manual httpd-manual as a component of Red Hat Enterprise Linux 9 | not affected vulnerable code not present | no version stated vendor label: httpd-manual | not applicable | csaf_redhat | |
| red_hat_jboss_enterprise_application_platform_6:httpd-manual httpd-manual as a component of Red Hat JBoss Enterprise Application Platform 6 | not affected vulnerable code not present | no version stated vendor label: httpd-manual | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_8:httpd-tools::httpd:2.4 httpd-tools (httpd:2.4) as a component of Red Hat Enterprise Linux 8 | not affected vulnerable code not present | httpd-tools::httpd:2.4 | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_6:httpd-tools httpd-tools as a component of Red Hat Enterprise Linux 6 | not affected vulnerable code not present | no version stated vendor label: httpd-tools | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_7:httpd-tools httpd-tools as a component of Red Hat Enterprise Linux 7 | not affected vulnerable code not present | no version stated vendor label: httpd-tools | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_9:httpd-tools httpd-tools as a component of Red Hat Enterprise Linux 9 | not affected vulnerable code not present | no version stated vendor label: httpd-tools | not applicable | csaf_redhat | |
| red_hat_jboss_enterprise_application_platform_6:httpd-tools httpd-tools as a component of Red Hat JBoss Enterprise Application Platform 6 | not affected vulnerable code not present | no version stated vendor label: httpd-tools | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_8:httpd.src::httpd:2.4 httpd.src (httpd:2.4) as a component of Red Hat Enterprise Linux 8 | not affected vulnerable code not present | httpd.src::httpd:2.4 | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_6:httpd.src httpd.src as a component of Red Hat Enterprise Linux 6 | not affected vulnerable code not present | no version stated vendor label: httpd.src | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_7:httpd.src httpd.src as a component of Red Hat Enterprise Linux 7 | not affected vulnerable code not present | no version stated vendor label: httpd.src | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_9:httpd.src httpd.src as a component of Red Hat Enterprise Linux 9 | not affected vulnerable code not present | no version stated vendor label: httpd.src | not applicable | csaf_redhat | |
| red_hat_jboss_enterprise_application_platform_6:httpd.src httpd.src as a component of Red Hat JBoss Enterprise Application Platform 6 | not affected vulnerable code not present | no version stated vendor label: httpd.src | not applicable | csaf_redhat | |
| red_hat_software_collections:httpd24-httpd httpd24-httpd as a component of Red Hat Software Collections | not affected vulnerable code not present | no version stated vendor label: httpd24-httpd | not applicable | csaf_redhat | |
| red_hat_software_collections:httpd24-httpd-devel httpd24-httpd-devel as a component of Red Hat Software Collections | not affected vulnerable code not present | no version stated vendor label: httpd24-httpd-devel | not applicable | csaf_redhat | |
| red_hat_software_collections:httpd24-httpd-manual httpd24-httpd-manual as a component of Red Hat Software Collections | not affected vulnerable code not present | no version stated vendor label: httpd24-httpd-manual | not applicable | csaf_redhat | |
| red_hat_software_collections:httpd24-httpd-tools httpd24-httpd-tools as a component of Red Hat Software Collections | not affected vulnerable code not present | no version stated vendor label: httpd24-httpd-tools | not applicable | csaf_redhat | |
| red_hat_software_collections:httpd24-httpd.src httpd24-httpd.src as a component of Red Hat Software Collections | not affected vulnerable code not present | no version stated vendor label: httpd24-httpd.src | not applicable | csaf_redhat | |
| red_hat_software_collections:httpd24-mod_ldap httpd24-mod_ldap as a component of Red Hat Software Collections | not affected vulnerable code not present | no version stated vendor label: httpd24-mod_ldap | not applicable | csaf_redhat | |
| red_hat_software_collections:httpd24-mod_md httpd24-mod_md as a component of Red Hat Software Collections | not affected vulnerable code not present | no version stated vendor label: httpd24-mod_md | not applicable | csaf_redhat | |
| red_hat_software_collections:httpd24-mod_proxy_html httpd24-mod_proxy_html as a component of Red Hat Software Collections | not affected vulnerable code not present | no version stated vendor label: httpd24-mod_proxy_html | not applicable | csaf_redhat | |
| red_hat_software_collections:httpd24-mod_session httpd24-mod_session as a component of Red Hat Software Collections | not affected vulnerable code not present | no version stated vendor label: httpd24-mod_session | not applicable | csaf_redhat | |
| red_hat_software_collections:httpd24-mod_ssl httpd24-mod_ssl as a component of Red Hat Software Collections | not affected vulnerable code not present | no version stated vendor label: httpd24-mod_ssl | not applicable | csaf_redhat | |
| red_hat_jboss_core_services:jbcs-httpd24-httpd jbcs-httpd24-httpd as a component of Red Hat JBoss Core Services | not affected vulnerable code not present | jbcs-httpd24-httpd | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_8:mod_http2::httpd:2.4 mod_http2 (httpd:2.4) as a component of Red Hat Enterprise Linux 8 | not affected vulnerable code not present | mod_http2::httpd:2.4 | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_8:mod_http2.src::httpd:2.4 mod_http2.src (httpd:2.4) as a component of Red Hat Enterprise Linux 8 | not affected vulnerable code not present | mod_http2.src::httpd:2.4 | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_8:mod_ldap::httpd:2.4 mod_ldap (httpd:2.4) as a component of Red Hat Enterprise Linux 8 | not affected vulnerable code not present | mod_ldap::httpd:2.4 | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_7:mod_ldap mod_ldap as a component of Red Hat Enterprise Linux 7 | not affected vulnerable code not present | no version stated vendor label: mod_ldap | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_9:mod_ldap mod_ldap as a component of Red Hat Enterprise Linux 9 | not affected vulnerable code not present | no version stated vendor label: mod_ldap | not applicable | csaf_redhat | |
| red_hat_jboss_enterprise_application_platform_6:mod_ldap mod_ldap as a component of Red Hat JBoss Enterprise Application Platform 6 | not affected vulnerable code not present | no version stated vendor label: mod_ldap | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_9:mod_lua mod_lua as a component of Red Hat Enterprise Linux 9 | not affected vulnerable code not present | no version stated vendor label: mod_lua | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_8:mod_md::httpd:2.4 mod_md (httpd:2.4) as a component of Red Hat Enterprise Linux 8 | not affected vulnerable code not present | mod_md::httpd:2.4 | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_8:mod_md.src::httpd:2.4 mod_md.src (httpd:2.4) as a component of Red Hat Enterprise Linux 8 | not affected vulnerable code not present | mod_md.src::httpd:2.4 | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_8:mod_proxy_html::httpd:2.4 mod_proxy_html (httpd:2.4) as a component of Red Hat Enterprise Linux 8 | not affected vulnerable code not present | mod_proxy_html::httpd:2.4 | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_7:mod_proxy_html mod_proxy_html as a component of Red Hat Enterprise Linux 7 | not affected vulnerable code not present | no version stated vendor label: mod_proxy_html | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_9:mod_proxy_html mod_proxy_html as a component of Red Hat Enterprise Linux 9 | not affected vulnerable code not present | no version stated vendor label: mod_proxy_html | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_8:mod_session::httpd:2.4 mod_session (httpd:2.4) as a component of Red Hat Enterprise Linux 8 | not affected vulnerable code not present | mod_session::httpd:2.4 | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_7:mod_session mod_session as a component of Red Hat Enterprise Linux 7 | not affected vulnerable code not present | no version stated vendor label: mod_session | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_9:mod_session mod_session as a component of Red Hat Enterprise Linux 9 | not affected vulnerable code not present | no version stated vendor label: mod_session | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_8:mod_ssl::httpd:2.4 mod_ssl (httpd:2.4) as a component of Red Hat Enterprise Linux 8 | not affected vulnerable code not present | mod_ssl::httpd:2.4 | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_6:mod_ssl mod_ssl as a component of Red Hat Enterprise Linux 6 | not affected vulnerable code not present | no version stated vendor label: mod_ssl | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_7:mod_ssl mod_ssl as a component of Red Hat Enterprise Linux 7 | not affected vulnerable code not present | no version stated vendor label: mod_ssl | not applicable | csaf_redhat | |
| red_hat_enterprise_linux_9:mod_ssl mod_ssl as a component of Red Hat Enterprise Linux 9 | not affected vulnerable code not present | no version stated vendor label: mod_ssl | not applicable | csaf_redhat | |
| red_hat_jboss_enterprise_application_platform_6:mod_ssl mod_ssl as a component of Red Hat JBoss Enterprise Application Platform 6 | not affected vulnerable code not present | no version stated vendor label: mod_ssl | not applicable | csaf_redhat | |
| apache | affected | >= 2.4.49, < 2.4.50 | vendor fix → 2.4.50 | osv BIT-apache-2021-42013 |
A claim with no version range is shown as written rather than expanded: a government catalog naming only a vendor and product is a real statement at zero granularity, and inventing bounds for it would put precision in the record that the source never offered.