Hello I’m running UCS version 5.0-2 errata492 with nextcloud 24.0.7-1
We had a security audit and the guy told us that our server is running Apache 2.4.38 which is vulnerable by this CVE-2020-11993. He recommends us to upgrade Apache to version 2.4.54 or higher
Anyone can help me with that please. Anyone upgrade Apache without the UCS GUI
Here is the output on my server
root@cloud:~# dpkg -l | grep apache
ii apache2 2.4.38-3+deb10u8A~5.0.2.202209111835 amd64 Apache HTTP Server
ii apache2-bin 2.4.38-3+deb10u8A~5.0.2.202209111835 amd64 Apache HTTP Server (modules and other binary files)
ii apache2-data 2.4.38-3+deb10u8A~5.0.2.202209111835 all Apache HTTP Server (common files)
ii apache2-suexec-pristine 2.4.38-3+deb10u8A~5.0.2.202209111835 amd64 Apache HTTP Server standard suexec program for mod_suexec
ii apache2-utils 2.4.38-3+deb10u8A~5.0.2.202209111835 amd64 Apache HTTP Server (utility programs for web servers)
ii libapache2-mod-authnz-pam 1.2.0-1 amd64 PAM authorization checker and PAM Basic Authentication provider
ii libapache2-mod-php7.0 7.0.33-0+deb9u10 amd64 server-side, HTML-embedded scripting language (Apache 2 module)
ii libapache2-mod-php7.3 7.3.31-1~deb10u1 amd64 server-side, HTML-embedded scripting language (Apache 2 module)
rc libapache2-mod-wsgi 4.5.11-1 amd64 Python WSGI adapter module for Apache
ii libapache2-mod-wsgi-py3 4.6.5-1+deb10u1 amd64 Python 3 WSGI adapter module for Apache
ii univention-apache 12.0.1-1A~5.0.0.202203041803 all UCS - Apache2 configuration
ii univention-apache-vhost 12.0.1-1A~5.0.0.202203041803 all UCS - Apache2 vhost
root@cloud:~#
Thanks !