CVE-2021-42013

Apache HTTP Server: Path Traversal

As of , CVE-2021-42013 in Apache HTTP Server is on CISA's list of exploited vulnerabilities: CISA listed it on . Our patch-first group: Patch this week.

Exploited
Yes: CISA listed it on 3 November 2021
US federal deadline
17 November 202114 days after CISA listed it. US federal civilian agencies must fix it by then.
Used in ransomware campaigns
Known
EPSS score
0.99Higher than 99% of the CVEs EPSS scores. EPSS estimates the chance of exploitation activity in the next 30 days.
EPSS when listed
Not availableCISA listed it before 4 February 2022, where the EPSS files we read begin.
Public exploit
2 Metasploit modules and 3 Exploit-DB entries (2 verified)
Fix
No vendor link in CISA's entry

What CISA says to do

Apply updates per vendor instructions.

CISA's required action

What the flaw is

Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by Alias-like directives are not under default require all denied or if CGI scripts are enabled. This CVE ID resolves an incomplete patch for CVE-2021-41773.

CISA's description

It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directories are not protected by the usual default configuration "require all denied", these requests can succeed. If CGI scripts are also enabled for these aliased pathes, this could allow for remote code execution. This issue only affects Apache 2.4.49 and Apache 2.4.50 and not earlier versions.

The CVE record's description, from apache

CVE published
7 October 2021
Assigned by
apache
CVSS
9.8 Critical (CVSS 3.1, from CISA-ADP)
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CISA SSVC, exploitation
active
CISA SSVC, automatable
yes
CISA SSVC, technical impact
total

Timeline

  1. The CVE record was published.
  2. Exploit-DB published an exploit (EDB-ID 50406).
  3. Exploit-DB published an exploit (EDB-ID 50446).
  4. CISA added it to its list of exploited vulnerabilities.
  5. Exploit-DB published an exploit (EDB-ID 50512).
  6. The US federal deadline to fix it.

Public exploits

Facts from Metasploit's module list and Exploit-DB's index; we never copy exploit code.

HTTP Server: other exploited entries

VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2021-41773Path TraversalApache HTTP ServerPatch this weekRansomware use; Metasploit module; EPSS 0.99; verified Exploit-DB entry0.99
CVE-2024-38475Improper Escaping of OutputApache HTTP ServerPatch this weekEPSS 0.990.99
CVE-2019-0211Privilege EscalationApache HTTP ServerPatch this weekEPSS 0.650.65

Read further