PT-2021-4295 · Apache+1 · Apache Http Server+1
Published
2021-10-07
·
Updated
2026-05-31
·
CVE-2021-42013
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Apache HTTP Server version 2.4.49
Apache HTTP Server version 2.4.50
Description
An insufficient fix for a previous path traversal issue allows a remote attacker to map URLs to files outside the directories configured by Alias-like directives. This occurs when files outside these directories are not protected by the default "require all denied" configuration. If CGI scripts are enabled for these aliased paths, the flaw can lead to remote code execution. Technical exploitation involves sending specially crafted HTTP requests, sometimes utilizing obfuscation such as
%%32%65 targeting /cgi-bin/.../bin/sh on ports 80 and 443.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
RCE
Path traversal
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Apache Http Server