CVE-2021-41773
A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directories are not protected by the usual default configuration "require all denied", these requests can succeed. If CGI scripts are also enabled for these aliased pathes, this could allow for remote code execution. This issue is known to be exploited in the wild. This issue only affects Apache 2.4.49 and not earlier versions. The fix in Apache HTTP Server 2.4.50 was found to be incomplete, see CVE-2021-42013.
- Affected products
- Alt Linux, Apache Http Server
- Apache Http Server
- = 2.4.49
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 100.0% (100th percentile)
- Weakness
- CWE-22
- NVD status
- Analyzed
- Published
- 2021-10-05
CVE-2021-41773 at NVD
100 known exploits for CVE-2021-41773
Proof-of-concept code and exploit modules indexed by Sploitus
zscan
CVE-2021-41773-Apache-RCE
CVE-2021-41773
cve-2021-41773
cve-2021-41773
CVE-2021-41773-exploit
CVE-2021-41773
apache-httpd-path-traversal-checker
CVE-2021-41773
CVE-2021-41773
CVE-2021-41773-RedTeam
apache2.4.49VulnerableLabSetup
CVE-2021-41773
CVE-2021-41773
CVE-2021-41773
CVE-2021-41773
CVE-2021-41773-exercise
Apache-CVE-2021-41773
CVE-2021-41773
CVE-2021-41773
CVE-2021-41773
POC-CVE-2021-41773
CVE-2021-41773
CVE-2021-41773-apache
mass_cve-2021-41773
CVE-2021-41773-Apache_2.4.49-Path-traversal-to-RCE
CVE-2021-41773-PoC
Scanner-CVE-2021-41773
CVE-2021-41773
CVE-2021-41773
apache-vulnerable
CVE-2021-41773m
CVE-2021-41773-PoC
CVE-2021-41773
CVE-2021-41773
CVE-2021-41773
cve-2021-41773-lab
CVE-2021-41773
cybersecurity_portfolio
CVE-2021-41773
CVE-2021-41773
CVE-2021-41773-exploiter
CVE-2021-41773
CVE-2021-42013
Reserch-CVE-2021-41773
cve-2021-41773-docker-lab
cve-2021-41773
CVE-2021-41773_CVE-2021-42013_Exploits
Path-traversal-RCE-Apache-2.4.49-2.4.50-Exploit
CVE-2021-41773
CVE-2021-41773-Exploit-Lab
CVE-2021-41773-Analysis
cve-2021-41773
apache_normalize_path
Apachuk
CVE-2021-41773
py-CVE-2021-41773
CVE-2021-41773-POC
CVE-2021-41773-PoC
Simple-CVE-2021-41773-checker
mass_cve-2021-41773
CVE-2021-41773
CVE-2021-41773-i-
CVE-2021-41773-L-
CVE-2021-41773.git1
CVE-2021-41773S
CVE-2021-41773h
cve-2021-41773
cve-2021-41773-v-
CVE-2021-41773
POC-CVE-2021-41773
apachrot
CVE-2021-41773
CVE-2021-41773
CVE-2021-41773
CVE-2021-41773
CVE-2021-41773
CVE-2021-41773
PoC-Apache-CVE-2021-41773-Infrastructure-LAB
CVE-2021-41773_CVE-2021-42013
CVE-2021-41773
CVE-2021-41773
CVE-2021-41773
cve-2021-41773
docker-lab-cve-2017-5638-cve-2021-41773
cve-analysis-exploitation-mitigation
CVE-2021-41773
CVE-2021-41773
SSH-key-and-RCE-PoC-for-CVE-2021-41773
exploit-apache2-cve-2021-41773
cve-2021-41773
CVE-2021-41773
Preproduce-CVE-2021-41773
CVE-2021-41773
CVE-2021-41773_Honeypot
POC-CVE-2021-41773
CVE-2021-41773-Apache-2.4.49-
CVE-2021-41773
CVE-2021-41773
CTF_WRITEUPS-TryHackMe-CVE-2021-41773-