Impact
Integer overflow in mod_dav_fs allows an authenticated WebDAV client with write access to issue PROPPATCH requests containing many XML namespaces, which triggers a crash in worker processes and permanently corrupts a directory’s property database.
Affected Systems
The vulnerability affects Apache HTTP Server versions up to and including 2.4.68. Only installations that have enabled the mod_dav_fs module and allow WebDAV write access are impacted.
Risk and Exploitability
Although the CVSS score is not provided, the flaw requires authentication and write permission, which limits the attack surface. The attack vector is likely an authenticated WebDAV client that can manipulate namespace declarations. Because it is not listed in CISA’s KEV catalog and no EPSS score is available, the likelihood of exploitation appears moderate, but the potential impact of a denial of service or data corruption can be severe for web applications relying on WebDAV functionality.
OpenCVE Enrichment