PT-2021-4295 · Apache+1 · Apache Http Server+1

Published

2021-10-07

·

Updated

2026-05-31

·

CVE-2021-42013

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Apache HTTP Server version 2.4.49 Apache HTTP Server version 2.4.50
Description An insufficient fix for a previous path traversal issue allows a remote attacker to map URLs to files outside the directories configured by Alias-like directives. This occurs when files outside these directories are not protected by the default "require all denied" configuration. If CGI scripts are enabled for these aliased paths, the flaw can lead to remote code execution. Technical exploitation involves sending specially crafted HTTP requests, sometimes utilizing obfuscation such as %%32%65 targeting /cgi-bin/.../bin/sh on ports 80 and 443.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Path traversal

OS Command Injection

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
ALT-PU-2021-2994
ALT-PU-2021-3013
ALT-PU-2021-3018
ALT-PU-2021-3037
ALT-PU-2021-3060
BDU:2021-04904
BIT-APACHE-2021-42013
CVE-2021-42013
MGASA-2021-0470
OPENSUSE-SU-2024:11560-1

Affected Products

Alt Linux
Apache Http Server