CVE Database
/

CVE-2021-41773

Back to search

CVE-2021-41773

Published: Oct 5, 2021

Modified: Oct 21, 2025

PUBLISHED

Description

A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directories are not protected by the usual default configuration "require all denied", these requests can succeed. If CGI scripts are also enabled for these aliased pathes, this could allow for remote code execution. This issue is known to be exploited in the wild. This issue only affects Apache 2.4.49 and not earlier versions. The fix in Apache HTTP Server 2.4.50 was found to be incomplete, see CVE-2021-42013.

VendorProductVersions

Apache Software Foundation

Apache HTTP Server

affected
Apache HTTP Server 2.4 2.4.49

Weaknesses (CWE)

References

FEDORA-2021-2a10bc68a4
vendor-advisory
x_refsource_FEDORA
FEDORA-2021-aaf90ef84a
vendor-advisory
x_refsource_FEDORA
GLSA-202208-20
vendor-advisory
x_refsource_GENTOO

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now