CVE-2022-24070
Apache Subversion vulnerability analysis and mitigation

Overview

CVE-2022-24070 affects Subversion's mod_dav_svn module, discovered in April 2022. The vulnerability impacts Subversion mod_dav_svn servers versions 1.10.0 through 1.14.1. This use-after-free vulnerability occurs while looking up path-based authorization rules, where mod_dav_svn servers may attempt to use memory which has already been freed. Servers that do not use mod_dav_svn are not affected (Debian Security, NVD).

Technical details

The vulnerability is a use-after-free issue that occurs specifically in the mod_dav_svn Apache HTTP server module. The issue manifests when the module attempts to access memory that has been previously freed while processing path-based authorization rules. This vulnerability affects the server-side components of Subversion when running under Apache HTTP Server (Red Hat CVE).

Impact

When exploited, this vulnerability can result in memory corruption and potential denial of service, specifically causing crashes of HTTP worker processes handling requests. This affects the stability and availability of Subversion services running under Apache HTTP Server (Debian Security).

Exploitability

The vulnerability can be triggered when processing path-based authorization rules in mod_dav_svn servers. The issue specifically affects server deployments using mod_dav_svn with Apache HTTP Server (Apache Bugzilla).

Mitigation and workarounds

The vulnerability has been fixed in Subversion version 1.14.2. Users are recommended to upgrade to this version or apply appropriate patches. For specific distributions: Debian has fixed the issue in version 1.10.4-1+deb10u3 for oldstable (buster) and version 1.14.1-3+deb11u1 for stable (bullseye) (Debian Security).

Additional resources


SourceThis report was generated using AI

Related Apache Subversion vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2024-45720HIGH7.8
  • Apache Subversion logoApache Subversion
  • subversion-ruby
NoYesOct 09, 2024
CVE-2022-24070HIGH7.5
  • Apache Subversion logoApache Subversion
  • subversion:1.14::subversion-devel
NoYesApr 12, 2022
CVE-2022-29046MEDIUM5.4
  • Java logoJava
  • subversion-libs
NoYesApr 12, 2022
CVE-2024-46901MEDIUM4.3
  • Apache Subversion logoApache Subversion
  • subversion:1.10:820250822173251:a51370e3::subversion-perl
NoYesDec 09, 2024
CVE-2022-29048MEDIUM4.3
  • Java logoJava
  • subversion
NoYesApr 12, 2022

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management