Impact
Apache HTTP Server’s mod_ssl contains an SSLRequire directive that can evaluate expressions against files. The vendor’s documentation reveals that the component incorrectly permits file‑related expression functions in the .htaccess context, allowing an attacker who can inject an expression to bypass authentication checks and obtain elevated privileges. This improper privilege management flaw may enable unauthorized code execution or access to protected resources on the server.
Affected Systems
The vulnerability exists in all releases of Apache HTTP Server from version 2.4.0 through 2.4.68, inclusive of all community and downstream distributions that have not upgraded. Any environment deploying these affected versions without mitigation remains susceptible.
Risk and Exploitability
The published CVSS score is 9.8 and the EPSS metric is unavailable, while the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a local or delegated write capability to the server’s configuration or .htaccess files, inferred from the requirement to inject a file‑related expression. Once such an expression is placed in a .htaccess file, the server will evaluate it as an SSLRequire rule, effectively granting the attacker privilege levels corresponding to the web server process. This can compromise confidentiality, integrity, and availability of the affected system.
OpenCVE Enrichment