Executive brief
A path traversal flaw in Apache HTTP Server 2.4.49 allows attackers to map URLs to files outside of configured directories. If CGI scripts are enabled for these aliased paths, the vulnerability can be leveraged for remote code execution.
Affected products
- Apache HTTP Server 2.4.49
Timeline
- 2021-10-05: disclosed: Initial public disclosure via mailing lists
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-03: advisory: NVD publication date
- exploited: Confirmed exploited in the wild