Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-42535

Опубликовано: 08 июн. 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 9.1

Описание

A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to directly manipulate trusted DAV property databases, potentially causing child process crashes. Users are recommended to upgrade to version 2.4.68, which fixes this issue.

РелизСтатусПримечание
devel

pending

2.4.68-1ubuntu2
esm-infra-legacy/trusty

released

2.4.7-1ubuntu4.22+esm14
esm-infra-legacy/xenial

released

2.4.18-2ubuntu3.17+esm19
esm-infra/bionic

released

2.4.29-1ubuntu4.27+esm10
esm-infra/focal

released

2.4.41-4ubuntu3.23+esm5
jammy

released

2.4.52-1ubuntu4.23
noble

released

2.4.58-1ubuntu8.15
questing

ignored

end of life, was needs-triage
resolute

released

2.4.66-2ubuntu2.4
upstream

released

2.4.68

Показывать по

EPSS

Процентиль: 44%
0.00538
Низкий

9.1 Critical

CVSS3

Связанные уязвимости

CVSS3: 6.5
redhat
3 месяца назад

A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to directly manipulate trusted DAV property databases, potentially causing child process crashes. Users are recommended to upgrade to version 2.4.68, which fixes this issue.

CVSS3: 9.1
nvd
3 месяца назад

A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to directly manipulate trusted DAV property databases, potentially causing child process crashes. Users are recommended to upgrade to version 2.4.68, which fixes this issue.

msrc
3 месяца назад

Apache HTTP Server: mod_dav_fs protected directory access

CVSS3: 9.1
debian
3 месяца назад

A path handling issue in mod_dav_fs in Apache 2.4.67 and earlierallows ...

CVSS3: 9.1
redos
около 2 месяцев назад

Уязвимость httpd

EPSS

Процентиль: 44%
0.00538
Низкий

9.1 Critical

CVSS3