Korzystamy z ciasteczek, aby ulepszać naszą stronę. Prosimy przeczytać naszą politykę dotyczącą ciasteczek .
2022-05-16
Severity
Status
The Apache Software Foundation announced multiple vulnerabilities that have been fixed in the latest release of Apache HTTP Server 2.4.53.
CVE-2022-22719 and CVE-2022-22720 will affect ASUSTOR products with Apache HTTP Server 2.4.52 installed.
CVE-2022-22721 and CVE-2022-23943 will not affect ASUSTOR products.
Product | Severity | Fixed Release Availability |
---|---|---|
ADM 4.0 | Important | Upgrade Apache HTTP Server to 2.4.53.r12 or above. |
ADM 3.5 | Moderate | Upgrade to 3.5.9.RTD2 or above. |
For ADM 3.5, administrators can disable Web Server service to mitigate the specific vulnerabilities. In environments where Web Server is still needed, changing the default Web Server port (80 and 443) can be used as temporary mitigation.
Revision | Date | Description |
---|---|---|
1 | 2022-04-20 | Initial public release. |
2 | 2022-05-04 | Update Apache HTTP Server to 2.4.53.r12 for fixing the issues on ADM 4.0. Update mitigation information for ADM 3.5. |
3 | 2022-05-16 | Release ADM 3.5.9.RTD2 to update Apache HTTP Server patch for fixing the issues. |
Copyright © 2025 ASUSTOR Inc.