{"cve": "CVE-2022-37436", "updated": null, "url": null, "affected": [{"ecosystem": "Arch", "package": "apache", "affected": "2.4.54-3", "fixed": "2.4.55-1", "status": "fixed", "ref": "https://security.archlinux.org/AVG-2824"}, {"ecosystem": "Debian:11", "package": "apache2", "affected": null, "fixed": "2.4.56-1~deb11u1", "status": "fixed", "ref": "https://osv.dev/vulnerability/DEBIAN-CVE-2022-37436"}, {"ecosystem": "Debian:12", "package": "apache2", "affected": null, "fixed": "2.4.55-1", "status": "fixed", "ref": "https://osv.dev/vulnerability/DEBIAN-CVE-2022-37436"}, {"ecosystem": "Debian:13", "package": "apache2", "affected": null, "fixed": "2.4.55-1", "status": "fixed", "ref": "https://osv.dev/vulnerability/DEBIAN-CVE-2022-37436"}, {"ecosystem": "Debian:14", "package": "apache2", "affected": null, "fixed": "2.4.55-1", "status": "fixed", "ref": "https://osv.dev/vulnerability/DEBIAN-CVE-2022-37436"}, {"ecosystem": "Debian:10", "package": "apache2", "affected": null, "fixed": "2.4.38-3+deb10u9", "status": "fixed", "ref": "https://osv.dev/vulnerability/DLA-3351-1"}, {"ecosystem": "Debian:11", "package": "apache2", "affected": null, "fixed": "2.4.56-1~deb11u1", "status": "fixed", "ref": "https://osv.dev/vulnerability/DSA-5376-1"}, {"ecosystem": "Ubuntu:Pro:14.04:LTS", "package": "apache2", "affected": null, "fixed": null, "status": "affected", "ref": "https://osv.dev/vulnerability/UBUNTU-CVE-2022-37436"}, {"ecosystem": "Ubuntu:Pro:16.04:LTS", "package": "apache2", "affected": null, "fixed": "2.4.18-2ubuntu3.17+esm9", "status": "fixed", "ref": "https://osv.dev/vulnerability/UBUNTU-CVE-2022-37436"}, {"ecosystem": "Ubuntu:18.04:LTS", "package": "apache2", "affected": null, "fixed": "2.4.29-1ubuntu4.26", "status": "fixed", "ref": "https://osv.dev/vulnerability/UBUNTU-CVE-2022-37436"}, {"ecosystem": "Ubuntu:20.04:LTS", "package": "apache2", "affected": null, "fixed": "2.4.41-4ubuntu3.13", "status": "fixed", "ref": "https://osv.dev/vulnerability/UBUNTU-CVE-2022-37436"}, {"ecosystem": "Ubuntu:22.04:LTS", "package": "apache2", "affected": null, "fixed": "2.4.52-1ubuntu4.3", "status": "fixed", "ref": "https://osv.dev/vulnerability/UBUNTU-CVE-2022-37436"}, {"ecosystem": "Ubuntu:18.04:LTS", "package": "apache2", "affected": null, "fixed": "2.4.29-1ubuntu4.26", "status": "fixed", "ref": "https://osv.dev/vulnerability/USN-5839-1"}, {"ecosystem": "Ubuntu:20.04:LTS", "package": "apache2", "affected": null, "fixed": "2.4.41-4ubuntu3.13", "status": "fixed", "ref": "https://osv.dev/vulnerability/USN-5839-1"}, {"ecosystem": "Ubuntu:22.04:LTS", "package": "apache2", "affected": null, "fixed": "2.4.52-1ubuntu4.3", "status": "fixed", "ref": "https://osv.dev/vulnerability/USN-5839-1"}, {"ecosystem": "Ubuntu:Pro:16.04:LTS", "package": "apache2", "affected": null, "fixed": "2.4.18-2ubuntu3.17+esm9", "status": "fixed", "ref": "https://osv.dev/vulnerability/USN-5839-2"}, {"ecosystem": "SUSE:OpenStack Cloud 9", "package": "apache2", "affected": null, "fixed": "2.4.23-29.94.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2023:0183-1"}, {"ecosystem": "SUSE:OpenStack Cloud Crowbar 9", "package": "apache2", "affected": null, "fixed": "2.4.23-29.94.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2023:0183-1"}, {"ecosystem": "SUSE:Linux Enterprise Server for SAP Applications 12 SP4", "package": "apache2", "affected": null, "fixed": "2.4.23-29.94.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2023:0183-1"}, {"ecosystem": "SUSE:Linux Enterprise Server 12 SP2-BCL", "package": "apache2", "affected": null, "fixed": "2.4.23-29.94.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2023:0183-1"}, {"ecosystem": "SUSE:Linux Enterprise Server 12 SP4-LTSS", "package": "apache2", "affected": null, "fixed": "2.4.23-29.94.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2023:0183-1"}, {"ecosystem": "SUSE:Linux Enterprise Software Development Kit 12 SP5", "package": "apache2", "affected": null, "fixed": "2.4.51-35.22.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2023:0185-1"}, {"ecosystem": "SUSE:Linux Enterprise Server 12 SP5", "package": "apache2", "affected": null, "fixed": "2.4.51-35.22.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2023:0185-1"}, {"ecosystem": "SUSE:Linux Enterprise Server for SAP Applications 12 SP5", "package": "apache2", "affected": null, "fixed": "2.4.51-35.22.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2023:0185-1"}, {"ecosystem": "SUSE:Linux Enterprise High Performance Computing 15 SP1-LTSS", "package": "apache2", "affected": null, "fixed": "2.4.33-150000.3.72.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2023:0294-1"}, {"ecosystem": "SUSE:Linux Enterprise Server 15 SP1-LTSS", "package": "apache2", "affected": null, "fixed": "2.4.33-150000.3.72.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2023:0294-1"}, {"ecosystem": "SUSE:Linux Enterprise Server for SAP Applications 15 SP1", "package": "apache2", "affected": null, "fixed": "2.4.33-150000.3.72.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2023:0294-1"}, {"ecosystem": "SUSE:Enterprise Storage 6", "package": "apache2", "affected": null, "fixed": "2.4.33-150000.3.72.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2023:0294-1"}, {"ecosystem": "SUSE:Linux Enterprise High Performance Computing 15 SP2-LTSS", "package": "apache2", "affected": null, "fixed": "2.4.51-150200.3.51.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2023:0321-1"}, {"ecosystem": "SUSE:Linux Enterprise High Performance Computing 15 SP3-ESPOS", "package": "apache2", "affected": null, "fixed": "2.4.51-150200.3.51.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2023:0321-1"}, {"ecosystem": "SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSS", "package": "apache2", "affected": null, "fixed": "2.4.51-150200.3.51.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2023:0321-1"}, {"ecosystem": "SUSE:Linux Enterprise Real Time 15 SP3", "package": "apache2", "affected": null, "fixed": "2.4.51-150200.3.51.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2023:0321-1"}, {"ecosystem": "SUSE:Linux Enterprise Server 15 SP2-LTSS", "package": "apache2", "affected": null, "fixed": "2.4.51-150200.3.51.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2023:0321-1"}, {"ecosystem": "SUSE:Linux Enterprise Server 15 SP3-LTSS", "package": "apache2", "affected": null, "fixed": "2.4.51-150200.3.51.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2023:0321-1"}, {"ecosystem": "SUSE:Linux Enterprise Server for SAP Applications 15 SP2", "package": "apache2", "affected": null, "fixed": "2.4.51-150200.3.51.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2023:0321-1"}, {"ecosystem": "SUSE:Linux Enterprise Server for SAP Applications 15 SP3", "package": "apache2", "affected": null, "fixed": "2.4.51-150200.3.51.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2023:0321-1"}, {"ecosystem": "SUSE:Manager Proxy 4.2", "package": "apache2", "affected": null, "fixed": "2.4.51-150200.3.51.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2023:0321-1"}, {"ecosystem": "SUSE:Manager Retail Branch Server 4.2", "package": "apache2", "affected": null, "fixed": "2.4.51-150200.3.51.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2023:0321-1"}, {"ecosystem": "SUSE:Manager Server 4.2", "package": "apache2", "affected": null, "fixed": "2.4.51-150200.3.51.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2023:0321-1"}, {"ecosystem": "SUSE:Enterprise Storage 7", "package": "apache2", "affected": null, "fixed": "2.4.51-150200.3.51.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2023:0321-1"}, {"ecosystem": "SUSE:Enterprise Storage 7.1", "package": "apache2", "affected": null, "fixed": "2.4.51-150200.3.51.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2023:0321-1"}, {"ecosystem": "SUSE:Linux Enterprise Module for Basesystem 15 SP4", "package": "apache2", "affected": null, "fixed": "2.4.51-150400.6.6.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2023:0322-1"}, {"ecosystem": "SUSE:Linux Enterprise Module for Package Hub 15 SP4", "package": "apache2", "affected": null, "fixed": "2.4.51-150400.6.6.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2023:0322-1"}, {"ecosystem": "SUSE:Linux Enterprise Module for Server Applications 15 SP4", "package": "apache2", "affected": null, "fixed": "2.4.51-150400.6.6.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2023:0322-1"}, {"ecosystem": "openSUSE:Leap 15.4", "package": "apache2", "affected": null, "fixed": "2.4.51-150400.6.6.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2023:0322-1"}, {"ecosystem": "SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS", "package": "apache2", "affected": null, "fixed": "2.4.66-150400.6.57.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2026:2686-1"}, {"ecosystem": "SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS", "package": "apache2", "affected": null, "fixed": "2.4.66-150400.6.57.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2026:2686-1"}, {"ecosystem": "SUSE:Linux Enterprise High Performance Computing 15 SP5-ESPOS", "package": "apache2", "affected": null, "fixed": "2.4.66-150400.6.57.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2026:2686-1"}, {"ecosystem": "SUSE:Linux Enterprise High Performance Computing 15 SP5-LTSS", "package": "apache2", "affected": null, "fixed": "2.4.66-150400.6.57.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2026:2686-1"}, {"ecosystem": "SUSE:Linux Enterprise Server 15 SP4-LTSS", "package": "apache2", "affected": null, "fixed": "2.4.66-150400.6.57.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2026:2686-1"}, {"ecosystem": "SUSE:Linux Enterprise Server 15 SP5-LTSS", "package": "apache2", "affected": null, "fixed": "2.4.66-150400.6.57.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2026:2686-1"}, {"ecosystem": "SUSE:Linux Enterprise Server for SAP Applications 15 SP4", "package": "apache2", "affected": null, "fixed": "2.4.66-150400.6.57.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2026:2686-1"}, {"ecosystem": "SUSE:Linux Enterprise Server for SAP Applications 15 SP5", "package": "apache2", "affected": null, "fixed": "2.4.66-150400.6.57.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/SUSE-SU-2026:2686-1"}, {"ecosystem": "openSUSE:Tumbleweed", "package": "apache2", "affected": null, "fixed": "2.4.55-1.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/openSUSE-SU-2024:12635-1"}, {"ecosystem": "Red Hat:enterprise_linux:8::appstream", "package": "httpd", "affected": null, "fixed": "0:2.4.37-51.module+el8.7.0+18026+7b169787.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2023:0852"}, {"ecosystem": "Red Hat:enterprise_linux:9::appstream", "package": "httpd", "affected": null, "fixed": "0:2.4.53-7.el9_1.1", "status": "fixed", "ref": "https://osv.dev/vulnerability/RHSA-2023:0970"}]}