S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 8, 2024

CVE-2021-42013 Scanner

CVE-2021-42013 scanner - Remote Code Execution (RCE) vulnerability in Apache HTTP Server

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.2k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2021-42013
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directories are not protected by the usual default configuration "require all denied", these requests can succeed. If CGI scripts are also enabled for these aliased pathes, this could allow for remote code execution. This issue only affects Apache 2.4.49 and Apache 2.4.50 and not earlier versions.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Apache HTTP Serverby Apache Software Foundation
Apache HTTP Server 2.4.49
Updated Aug 21, 2026View on NVD →
Detail

Apache HTTP Server is a popular open-source web server software used to host websites and web applications. It is known for its flexibility, stability, and security, and it is used by millions of websites around the world. The purpose of Apache HTTP Server is to provide a reliable and secure platform for serving content over the World Wide Web. It is designed to work across multiple operating systems and can be easily configured for many different use cases.

Recently, a vulnerability was detected in Apache HTTP Server 2.4.49 and 2.4.50, which can allow a remote attacker to execute arbitrary code on the server. The vulnerability is identified as CVE-2021-42013, and it allows an attacker to perform a path traversal attack, which causes URLs to map to files outside the directories that are configured by Alias-like directives.

When the vulnerability is exploited, an attacker can access files that are outside the configured directories, leading to a potential data breach. This can include sensitive files or scripts that contain user data, access credentials, or other confidential information. Furthermore, if CGI scripts are enabled for the affected paths, the attacker can execute arbitrary code on the server, leading to a complete compromise of the system.

At s4e.io, we provide a comprehensive platform for identifying, analyzing, and mitigating vulnerabilities in digital assets. Our pro features allow users to quickly and easily scan their web applications and servers for vulnerabilities, including CVE-2021-42013. With our platform, users can stay ahead of potential threats and protect their digital assets from unauthorized access, data breaches, and other security risks.

 

REFERENCES

Solution Advice

To protect against this vulnerability, it is recommended to apply the patches that have been released by the Apache HTTP Server project. Additionally, it is advised to follow the best practices for securing web servers, including:

  • Regularly update software and plugins
  • Use strong passwords
  • Implement access control measures
  • Monitor network traffic and logs
  • Use web application firewalls

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.