{"api_version":"v1","generated_at":"2026-10-07T11:40:00+00:00","product":{"cve_count":4,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-apache-software-foundation-apache-portable-runtime-apr-727084318412","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"Apache Portable Runtime (APR)","next_cursor":null,"observations":[{"affected":"0.9.0 \u2264 1.7.4","affected_versions_present":true,"cve_id":"CVE-2023-49582","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-49582","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-03-13T14:25:56.517Z","patch_url":"","primary_source":"","published":"2024-08-26T14:03:44.588Z"},{"affected":"\u2264 1.7.0","affected_versions_present":true,"cve_id":"CVE-2022-28331","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-28331","fixed":"Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258","last_modified":"2025-03-27T14:31:30.494Z","patch_url":"https://access.redhat.com/security/cve/CVE-2022-28331","primary_source":"","published":"2023-01-31T15:55:21.488Z"},{"affected":"1.7.0","affected_versions_present":true,"cve_id":"CVE-2022-24963","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-24963","fixed":"Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258","last_modified":"2025-03-27T14:33:39.826Z","patch_url":"https://access.redhat.com/security/cve/CVE-2022-24963","primary_source":"","published":"2023-01-31T15:52:09.716Z"},{"affected":"Apache Portable Runtime 1.7.0","affected_versions_present":true,"cve_id":"CVE-2021-35940","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-35940","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-04T00:40:47.582Z","patch_url":"https://dist.apache.org/repos/dist/release/apr/patches/apr-1.7.0-CVE-2021-35940.patch","primary_source":"","published":"2021-08-23T10:00:10.000Z"}],"source_generated_at":"2026-10-07T06:21:30.017Z","vendor":"Apache Software Foundation"}}
