2.3 Ensure the WebDAV Modules Are Disabled

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version


The Apache 'mod_dav' and 'mod_dav_fs' modules support WebDAV ('Web-based Distributed Authoring and Versioning') functionality for Apache. WebDAV is an extension to the HTTP protocol which allows clients to create, move, and delete files and resources on the web server.


Disabling WebDAV modules will improve the security posture of the web server by reducing the amount of potentially vulnerable code paths exposed to the network and reducing potential for unauthorized access to files via misconfigured WebDAV access controls.


Perform either one of the following to disable WebDAV module:

1. For source builds with static modules run the Apache './configure' script without including the 'mod_dav', and 'mod_dav_fs' in the '--enable-modules=configure' script options.

$ ./configure

2. For dynamically loaded modules comment out or remove the 'LoadModule' directive for 'mod_dav', and 'mod_dav_fs' modules from the 'httpd.conf' file.

##LoadModule dav_module modules/mod_dav.so
##LoadModule dav_fs_module modules/mod_dav_fs.so

See Also


Item Details


References: 800-53|CM-7, CSCv6|9.1, CSCv7|9.2

Plugin: Unix

Control ID: ac6f0f6741c6cbc526149abb34bbfa01b8d3ad2fd5a9d0b4519853d063d6f3e3