Junglewise Threat Intelligence

CVE-2021-42013: Apache HTTP Server Path Traversal Vulnerability

CVE-2021-42013 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2021-11-03

Technologies: Apache HTTP Server. Vendors: Apache.

Executive brief

An incomplete patch for CVE-2021-41773 in Apache HTTP Server 2.4.50 allows for path traversal and potential remote code execution. Attackers can map URLs to files outside the document root if Alias-like directives are used without 'require all denied' protections, or execute arbitrary code if CGI scripts are enabled.

Affected products

  • Apache HTTP Server 2.4.49, 2.4.50

Timeline

  • 2021-11-03: disclosed
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: advisory: NVD publication date

Related threats