A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directories are not protected by the usual default configuration "require all denied", these requests can succeed. If CGI scripts are also enabled for these aliased pathes, this could allow for remote code execution. This issue is known to be exploited in the wild. This issue only affects Apache 2.4.49 and not earlier versions. The fix in Apache HTTP Server 2.4.50 was found to be incomplete, see CVE-2021-42013.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade apache2 | Aug 22, 2024 | Oct 5, 2021 |
| Amazon Linux Ami 2 | — | Upgrade mod_proxy_htmlUpgrade httpd-debuginfoUpgrade httpd-manualUpgrade httpd-filesystemUpgrade mod_mdUpgrade httpd-develUpgrade mod_sslUpgrade httpd-toolsUpgrade mod_sessionUpgrade httpdUpgrade mod_ldap | Oct 18, 2021 | Oct 18, 2021 |
| Amazon_linux | — | Upgrade httpd24 | Oct 16, 2021 | Oct 5, 2021 |
| Apache Httpd | — | Upgrade to the latest version of Apache HTTPD | Oct 6, 2021 | Oct 5, 2021 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Oct 5, 2021 |
| Check Point Gaia | — | Upgrade to supported version Check Point Gaia. | Feb 25, 2026 | Oct 27, 2021 |
| Debian | — | Upgrade apache2 | Jul 30, 2024 | Oct 5, 2021 |
| Freebsd | — | Upgrade apache24 | Nov 4, 2022 | Oct 5, 2021 |
| Gentoo Linux | — | Upgrade app-admin/apache-tools.Upgrade www-servers/apache. | Aug 16, 2022 | Oct 5, 2021 |
| Oracle Solaris | — | Upgrade web/server/apache-24/module/apache-ssl-fips-140 to version 2.4.51-11.4.38.0.1.101.6 on Solaris 11.4Upgrade web/server/apache-24/module/apache-ssl to version 2.4.51-11.4.38.0.1.101.6 on Solaris 11.4Upgrade web/server/apache-24/module/apache-dbd to version 2.4.51-11.4.38.0.1.101.6 on Solaris 11.4Upgrade web/server/apache-24/module/apache-ldap to version 2.4.51-11.4.38.0.1.101.6 on Solaris 11.4Upgrade web/server/apache-24/module/apache-gss to version 2.4.51-11.4.38.0.1.101.6 on Solaris 11.4Upgrade web/server/apache-24/module/apache-lua to version 2.4.51-11.4.38.0.1.101.6 on Solaris 11.4Upgrade web/server/apache-24 to version 2.4.51-11.4.38.0.1.101.6 on Solaris 11.4 | Nov 17, 2021 | Nov 17, 2021 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Oct 5, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub