CVE-2021-41773: Apache HTTP Server Path Traversal
A path traversal flaw in a change made to Apache HTTP Server 2.4.49's URL path normalization, letting a crafted request map outside the configured document root to read arbitrary files, and, if mod_cgi is enabled for the mapped path, achieve remote code execution. The follow-up release 2.4.50 shipped an incomplete fix, tracked separately as CVE-2021-42013.
View the authoritative record on NVD ↗Affected software
- Apache HTTP Server 2.4.49 (and 2.4.50 for the incomplete-fix variant)
How it's exploited
Send a GET request with URL-encoded traversal sequences (such as /icons/.%2e/%2e%2e/etc/passwd) that bypass the path normalization added in 2.4.49, escaping the document root to read arbitrary files, or execute commands if the traversed path is CGI-enabled.
Severity
CVE-2021-41773 carries a CVSS 3.1 base score of 7.5, rated High. See how CVSS scoring works or score a vulnerability yourself with the free CVSS calculator.
Weakness type
CVE-2021-41773 is categorized under CWE-22, the general weakness pattern behind this specific vulnerability.
How TurboPentest tests for this
TurboPentest's automated black-box pentest actively probes for Path Traversal using OWASP ZAP and Nuclei and FFUF, with no source code required. Connecting a GitHub repo adds white-box confirmation from IntegSec's Opengrep SAST rule pack, which carries 9 dedicated rules for this weakness.
Tools: OWASP ZAP, Nuclei, FFUF
Remediation
Upgrade to Apache HTTP Server 2.4.51 or later; 2.4.50 alone is not sufficient, since its fix for this issue was incomplete.
Frequently asked questions
What is CVE-2021-41773?
A path traversal flaw in a change made to Apache HTTP Server 2.4.49's URL path normalization, letting a crafted request map outside the configured document root to read arbitrary files, and, if mod_cgi is enabled for the mapped path, achieve remote code execution. The follow-up release 2.4.50 shipped an incomplete fix, tracked separately as CVE-2021-42013.
How severe is CVE-2021-41773?
CVE-2021-41773 has a CVSS 3.1 base score of 7.5 out of 10, rated High.
What software is affected by CVE-2021-41773?
CVE-2021-41773 affects Apache HTTP Server 2.4.49 (and 2.4.50 for the incomplete-fix variant).
How do you fix CVE-2021-41773?
Upgrade to Apache HTTP Server 2.4.51 or later; 2.4.50 alone is not sufficient, since its fix for this issue was incomplete.
Where is the authoritative record for CVE-2021-41773?
The National Vulnerability Database (NVD) publishes the authoritative record for CVE-2021-41773 at https://nvd.nist.gov/vuln/detail/CVE-2021-41773, including the current CVSS score, CWE mapping, and affected-configuration data.
Related CVEs
- CVSS 9.8 CriticalCVE-2021-21972: vCenter Server RCE
- CVSS 9.8 CriticalCVE-2019-19781: Citrix ADC Path Traversal RCE
- CVSS 10.0 CriticalCVE-2019-11510: Pulse Secure Arbitrary File Read
- CVSS 9.8 CriticalCVE-2018-13379: FortiOS SSL VPN Path Traversal
- CVSS 10.0 CriticalCVE-2021-44228: Log4Shell
- CVSS 9.8 CriticalCVE-2021-26855: ProxyLogon
About this reference
These security references are maintained by IntegSec, an offensive-security firm whose team holds CISSP, OSCP, and OSCE certifications and has run thousands of penetration tests. Content is kept current as tools, standards, and attack techniques evolve.
Find known-vulnerable services before an attacker does
TurboPentest fingerprints every open port and web service, then matches detected versions against known CVEs automatically, from $99 per target.
Start a pentest