Impact
A path handling flaw in mod_dav_fs of Apache HTTP Server up to version 2.4.67 allows an authenticated WebDAV content author to directly manipulate trusted DAV property databases. This weakness, classified as CWE‑22 and CWE‑668, can cause child process crashes, resulting in a loss of service availability.
Affected Systems
The vulnerability affects Apache HTTP Server versions 2.4.67 and earlier. The affected product is the Apache Software Foundation’s Apache HTTP Server; no other vendors or sub‑products are listed.
Risk and Exploitability
The EPSS score is < 1% and the vulnerability is not listed in CISA KEV. The CVSS score is 9.1. Based on the description, the likely attack vector is a remote WebDAV client that has content author privileges to the server. The flaw involves path handling that permits manipulation of property files (CWE‑22), so an attacker can influence internal file paths to corrupt or overwrite DAV property databases, triggering child process crashes. No additional prerequisites are specified. Because the flaw can crash child processes, a remote attacker who can perform WebDAV operations may trigger a denial of service.
OpenCVE Enrichment
Debian DLA