important · Privilege
Apache 2.4.68’s tenant-boundary fix missed mod_ssl SSLRequire.
Affects
Apache HTTP Server 2.4 installations using mod_ssl and permitting lower-privileged users or hosting tenants to author .htaccess files.
A tenant who can write .htaccess rules in an eligible mod_ssl directory can still invoke file functions with the httpd process’s filesystem authority.
Detail and 2 sources
Apache identifies 2.4.69 as the release that adds the omitted restriction.