Executive brief
An incomplete patch for CVE-2021-41773 in Apache HTTP Server 2.4.50 allows for path traversal and potential remote code execution. Attackers can map URLs to files outside the document root if Alias-like directives are used without 'require all denied' protections, or execute arbitrary code if CGI scripts are enabled.
Affected products
- Apache HTTP Server 2.4.49, 2.4.50
Timeline
- 2021-11-03: disclosed
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-03: advisory: NVD publication date