
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2022-24070 affects Subversion's mod_dav_svn module, discovered in April 2022. The vulnerability impacts Subversion mod_dav_svn servers versions 1.10.0 through 1.14.1. This use-after-free vulnerability occurs while looking up path-based authorization rules, where mod_dav_svn servers may attempt to use memory which has already been freed. Servers that do not use mod_dav_svn are not affected (Debian Security, NVD).
The vulnerability is a use-after-free issue that occurs specifically in the mod_dav_svn Apache HTTP server module. The issue manifests when the module attempts to access memory that has been previously freed while processing path-based authorization rules. This vulnerability affects the server-side components of Subversion when running under Apache HTTP Server (Red Hat CVE).
When exploited, this vulnerability can result in memory corruption and potential denial of service, specifically causing crashes of HTTP worker processes handling requests. This affects the stability and availability of Subversion services running under Apache HTTP Server (Debian Security).
The vulnerability can be triggered when processing path-based authorization rules in mod_dav_svn servers. The issue specifically affects server deployments using mod_dav_svn with Apache HTTP Server (Apache Bugzilla).
The vulnerability has been fixed in Subversion version 1.14.2. Users are recommended to upgrade to this version or apply appropriate patches. For specific distributions: Debian has fixed the issue in version 1.10.4-1+deb10u3 for oldstable (buster) and version 1.14.1-3+deb11u1 for stable (bullseye) (Debian Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."