PT-2021-4294 · Apache+1 · Apache Http Server+1

CVE-2021-41773

·

Published

2021-10-04

·

Updated

2026-06-12

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache HTTP Server versions 2.4.49 through 2.4.50
Description A flaw in path normalization allows a path traversal attack to map URLs to files outside directories configured by Alias-like directives. If these files are not protected by the default "require all denied" configuration, requests can succeed. If CGI scripts are enabled for these paths, remote code execution may be possible. This issue has been exploited in the wild, with some reports indicating approximately 112,000 vulnerable hosts. Technical exploitation involves using encoded characters such as .%2e/ to access sensitive files like /etc/passwd or executing commands via /cgi-bin/.../bin/sh.
Recommendations Update Apache HTTP Server to a version later than 2.4.50. As a temporary workaround, ensure the "require all denied" configuration is applied to directories outside the intended alias paths. Restrict access to the cgi-bin directory or disable CGI scripts to minimize the risk of remote code execution.

Exploit

Fix

RCE

DoS

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2021_3816
ALSA-2022_0891
ALSA-2022_1915
ALSA-2023_1670
ALSA-2023_1673
ALSA-2025_16880
ALT-PU-2021-2994
ALT-PU-2021-3018
ALT-PU-2021-3037
ALT-PU-2021-3060
BDU:2021-04903
BIT-APACHE-2021-41773
CVE-2021-41773
MGASA-2021-0461
OPENSUSE-SU-2024:11560-1

Affected Products

Alt Linux
Apache Http Server