- 
    Thu Mar 24 2022 Kevin Lyons <kevin.x.lyons@oracle.com> - 2.4.37-43.0.2.3
    
- Set vstring per ORACLE_SUPPORT_PRODUCT [Orabug: 29892262]
- Replace index.html with Oracle's index page oracle_index.html
   
  
  - 
    Mon Mar 21 2022 Luboš Uhliarik <luhliari@redhat.com> - 2.4.37-43.3
    
- Resolves: #2065247 - CVE-2022-22720 httpd:2.4/httpd: HTTP request smuggling
  vulnerability in Apache HTTP Server 2.4.52 and earlier
   
  
  - 
    Fri Feb 25 2022 Luboš Uhliarik <luhliari@redhat.com> - 2.4.37-43.2
    
- Resolves: #2059256 - CVE-2021-34798 httpd:2.4/httpd: NULL pointer dereference
  via malformed requests
- Resolves: #2059257 - CVE-2021-39275 httpd:2.4/httpd: out-of-bounds write in
  ap_escape_quotes() via malicious input
   
  
  - 
    Mon Jan 10 2022 Luboš Uhliarik <luhliari@redhat.com> - 2.4.37-43.1
    
- Resolves: #2035062 - CVE-2021-44790 httpd:2.4/httpd: mod_lua: possible buffer
  overflow when parsing multipart content
   
  
  - 
    Tue Oct 26 2021 Luboš Uhliarik <luhliari@redhat.com> - 2.4.37-43
    
- Related: #2007235 - CVE-2021-40438 httpd:2.4/httpd: mod_proxy: SSRF via
  a crafted request uri-path
   
  
  - 
    Thu Sep 30 2021 Luboš Uhliarik <luhliari@redhat.com> - 2.4.37-42
    
- Resolves: #2007235 - CVE-2021-40438 httpd:2.4/httpd: mod_proxy: SSRF via
  a crafted request uri-path
- Resolves: #2014063 - CVE-2021-26691 httpd:2.4/httpd: Heap overflow in
  mod_session
   
  
  - 
    Fri Jul 09 2021 Luboš Uhliarik <luhliari@redhat.com> - 2.4.37-41
    
- Resolves: #1680111 - httpd sends reply to HTTPS GET using two TLS records
- Resolves: #1905613 - mod_ssl does not like valid certificate chain
- Resolves: #1935742 - [RFE] backport samesite/httponly/secure flags for
  usertrack
- Resolves: #1972500 - CVE-2021-30641 httpd:2.4/httpd: MergeSlashes regression
- Resolves: #1968307 - CVE-2021-26690 httpd:2.4/httpd: mod_session NULL pointer
  dereference in parser
- Resolves: #1934741 - Apache trademark update - new logo
   
  
  - 
    Fri May 14 2021 Lubos Uhliarik <luhliari@redhat.com> - 2.4.37-40
    
- Resolves: #1952557 - mod_proxy_wstunnel.html is a malformed XML
- Resolves: #1937334 - SSLProtocol with based virtual hosts
   
  
  - 
    Tue Jan 26 2021 Artem Egorenkov <aegorenk@redhat.com> - 2.4.37-39
    
- prevent htcacheclean from while break when first file processed
   
  
  - 
    Tue Jan 26 2021 Lubos Uhliarik <luhliari@redhat.com> - 2.4.37-38
    
- Resolves: #1918741 - Thousands of /tmp/modproxy.tmp.* files created by apache