PT-2021-4294 · Apache +1 · Apache Http Server +1

Published

2021-10-04

·

Updated

2026-01-26

·

CVE-2021-41773

CVSS v2.0
9.3
VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Apache HTTP Server versions 2.4.49 and 2.4.50 Apache HTTP Server version 2.4.49
Description A path traversal flaw was discovered in Apache HTTP Server 2.4.49. An attacker can exploit this to map URLs to files outside of configured directories. If files outside these directories are not protected by default configurations, requests can succeed. Enabling CGI scripts for these aliased paths could allow for remote code execution. This issue is actively exploited in the wild. The initial fix in version 2.4.50 was incomplete.
Recommendations Upgrade to a version later than 2.4.50.

Exploit

Fix

RCE

Path traversal

Weakness Enumeration

Related Identifiers

ALSA-2021_3816
ALSA-2022_0891
ALSA-2022_1915
ALSA-2023_1670
ALSA-2023_1673
ALSA-2025_16880
ALT-PU-2021-2994
ALT-PU-2021-3018
ALT-PU-2021-3037
ALT-PU-2021-3060
BDU:2021-04903
BIT-APACHE-2021-41773
CVE-2021-41773
MGASA-2021-0461
OPENSUSE-SU-2024:11560-1

Affected Products

Alt Linux
Apache Http Server