SUMMARY cPanel, L.L.C. has updated packages for EasyApache 4 with Apache version 2.4.53. This release addresses vulnerabilities related to CVE-2022-23943, CVE-2022-22721, CVE-2022-22720, and CVE-2022-22719. We strongly encourage all Apache 2.4 users to upgrade to version 2.4.53. AFFECTED VERSIONS All versions of Apache through 2.4.52. SECURITY RATING The National Vulnerability Database (NIST) has given the following severity ratings to these CVEs: CVE-2022-23943 - MEDIUM Apache 2.4.53 Fixed vulnerability in mod_sed module related to CVE-2021-23943. CVE-2022-22721 - MEDIUM Apache 2.4.53 Fixed vulnerability in Core module related to CVE-2021-22721. CVE-2022-22720 - MEDIUM Apache 2.4.53 Fixed vulnerability with inbound requests related to CVE-2021-22720. CVE-2022-22719 - MEDIUM Apache 2.4.53 Fixed vulnerability in mod_lua related to CVE-2021-22719. SOLUTION cPanel, L.L.C. has released updated packages for EasyApache 4 on March 16, 2022, with Apache version 2.4.53. Unless you have enabled automatic package updates in your cron, update your system with either your package manager or WHM's Run System Update interface. REFERENCES https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-22719 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-22720 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-22721 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-22943 https://downloads.apache.org/httpd/CHANGES_2.4.53