S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-41773 Scanner

CVE-2021-41773 scanner - Path Traversal vulnerability in Apache HTTP Server

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.4k
Times Used
continuous scan runs
3.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2021-41773
9.8
CVSShigh
Exploitable remotely over the internet · no authentication required.

A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directories are not protected by the usual default configuration "require all denied", these requests can succeed. If CGI scripts are also enabled for these aliased pathes, this could allow for remote code execution. This issue is known to be exploited in the wild. This issue only affects Apache 2.4.49 and not earlier versions. The fix in Apache HTTP Server 2.4.50 was found to be incomplete, see CVE-2021-42013.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Apache HTTP Serverby Apache Software Foundation
Apache HTTP Server 2.4 2.4.49
Updated Aug 21, 2026View on NVD →
Detail

Apache HTTP Server is an open-source web server software that is widely used across the internet in powering websites and web applications. It is commonly used in hosting platforms, content delivery networks, and popular web applications such as WordPress, Drupal and Joomla. Apache HTTP Server is renowned for its flexibility, security and compatibility with various operating systems, including Windows, Linux and macOS.

CVE-2021-41773 is the code given to a severe vulnerability that was identified in Apache HTTP Server 2.4.49. A flaw was detected in the path normalization during URL mapping, which could allow attackers to map URLs to files outside the folders configured by Alias-like directives. If CGI scripts are enabled for these aliased paths, the vulnerability could allow attackers to execute remote code. This vulnerability is known to be actively exploited by attackers.

Exploitation of CVE-2021-41773 could lead to catastrophic consequences for vulnerable web applications. Attackers can exploit this vulnerability to bypass access controls and access sensitive files outside the configured directories. Attackers can also execute arbitrary code on affected web servers, leading to complete compromise of the system and the theft of confidential data.

Thanks to the pro features of s4e.io, readers can easily learn about vulnerabilities in their digital assets. s4e.io offers a user-friendly and intuitive platform for vulnerability scanning and detection across a variety of digital assets. It empowers businesses and individuals to stay ahead of cyber threats by providing comprehensive reports pinpointing vulnerabilities and providing step-by-step instructions to remediate detected vulnerabilities.

 

REFERENCES

Solution Advice

To protect against CVE-2021-41773 vulnerability, it's critical to take the following precautions:

  • Install and configure the patch available in Apache HTTP Server 2.4.50+.
  • Disable all CGI script support in untrusted directories.
  • Sanitize user input and implement access control for web applications.
  • Harden file permissions for sensitive files and directories.
  • Monitor web servers for any unusual activities and log all server activities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.