WA00505 A22 - Web Distributed Authoring and Versioning (WebDAV) must be disabled.

Information

The Apache mod_dav and mod_dav_fs modules support WebDAV ('Web-based Distributed Authoring and Versioning') functionality for Apache. WebDAV is an extension to the HTTP protocol which allows clients to create, move, and delete files and resources on the web server. WebDAV is not widely used, and has serious security concerns as it may allow clients to modify unauthorized files on the web server. Therefore, the WebDav modules mod_dav and mod_dav_fs should be disabled.

Solution

Edit the httpd.conf file and remove the following modules:

dav_module
dav_fs_module
dav_lock_module

See Also

https://iasecontent.disa.mil/stigs/zip/U_Apache_2-2_UNIX_V1R11_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b., CAT|II, Rule-ID|SV-33216r1_rule, STIG-ID|WA00505_A22, Vuln-ID|V-26287

Plugin: Unix

Control ID: 829fea320976815925717d896fdc7d32c4cebbb55369bf2a4edbb87c2db2d7a0