← back
CVE-2022-24070

Apache Subversion mod_dav_svn is vulnerable to memory corruption

EPSS 8.8%CWE-416
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS EPSS 8.8%KEV nãoPoC Nuclei Metasploit Patch referenciado
Lifecycle
12 Apr 2022Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Subversion's mod_dav_svn is vulnerable to memory corruption. While looking up path-based authorization rules, mod_dav_svn servers may attempt to use memory which has already been freed. Affected Subversion mod_dav_svn servers 1.10.0 through 1.14.1 (inclusive). Servers that do not use mod_dav_svn are not affected.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →