Impact
The vulnerability exploits a path equivalence condition in Apache HTTP Server’s mod_userdir module, where the '/./' (single dot directory) notation is treated as equivalent to the parent directory. When mod_userdir is configured with an absolute non-wildcard UserDir directive, an attacker can supply specially crafted URLs to access files outside the intended user directory and potentially retrieve content from the server’s file system. This results in unauthorized disclosure of sensitive files that may contain configuration data or user data, compromising confidentiality. The weakness is identified as CWE-55, which denotes improper handling of path equivalence and precursors to directory traversal faults.
Affected Systems
All installations of Apache HTTP Server versions 2.4.0 through 2.4.68 that enable the mod_userdir module with an absolute non‑wildcard UserDir directive are affected. The vulnerability does not require any additional services or modules beyond the standard mod_userdir configuration and therefore applies to any web server instance using this directive within the stated version range.
Risk and Exploitability
The vulnerability is remotely exploitable via standard HTTP requests, as an attacker only needs to direct a URI containing the vulnerable path equivalence pattern to the affected server. The EPSS score is not available, indicating that the exploitation likelihood is not quantified at this time, but the absence of a KEV listing suggests it has not been documented as a known exploited vulnerability. Nonetheless, the remote nature of the attack vector, the ability to gain access to arbitrary files, and the broad version scope imply a high potential impact for any affected deployment. Deployers should therefore treat this as a high‑risk condition until mitigated.
OpenCVE Enrichment