Impact
A path handling flaw in mod_dav_fs of Apache HTTP Server up to version 2.4.67 allows an authenticated WebDAV content author to directly manipulate trusted DAV property databases. This weakness, classified as CWE‑668, can cause child process crashes, resulting in a loss of service availability and potential data integrity issues.
Affected Systems
The vulnerability affects Apache HTTP Server versions 2.4.67 and earlier. The affected product is the Apache Software Foundation’s Apache HTTP Server; no other vendors or sub‑products are listed.
Risk and Exploitability
The EPSS score is not available and the vulnerability is not listed in CISA KEV. No CVSS score is provided in the data. Based on the description, the likely attack vector is a remote WebDAV client that has content author privileges to the server. No additional prerequisites are specified. Because the flaw can crash child processes, a remote attacker who can perform WebDAV operations may trigger a denial of service.
OpenCVE Enrichment