The Apache Software Foundation has released a new version of the Apache HTTP Server, 2.4.52, to address two flaws – one scored high and the other critical – in one of the world’s leading web servers. Security practitioners racing to mitigate Apache’s logging library vulnerabilities – known as Log4j – these newly detected vulnerabilities in Apache’s server software now may be leveraged for remote access, some experts say. The high-ranked vulnerability affects HTTP server version 2.7 and could allow for configuration mixing forward and reverse proxy declarations, leading to a crash when ProxyRequests are turned on.”]
Source: https://www.inforisktoday.com/2-vulnerabilities-discovered-in-apache-http-server-a-18208

