Impact
Apache HTTP Server versions prior to 2.4.69 on all platforms include a flaw in the mod_dav_fs component that allows remote clients to access internal state files. By issuing a simple GET request to the ".DAV" state directory, an attacker can retrieve the dead properties of WebDAV resources that the client cannot normally modify. This exposure allows the attacker to read the dead properties of WebDAV resources.
Affected Systems
The vulnerability affects Apache HTTP Server releases from 2.4.0 through 2.4.68. All operating systems that run these versions are potentially impacted, regardless of platform.
Risk and Exploitability
The vulnerability can be exploited by a remote client over HTTP. The CVSS score is 5.3, indicating a moderate severity. EPSS score is not available, and the issue is not listed in the CISA KEV catalog.
OpenCVE Enrichment