Path traversal in Apache HTTP Server - CVE-2021-41773
Published: October 5, 2021 / Updated: May 7, 2023
Vulnerability details
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences. A remote attacker can send a specially crafted HTTP request to map URLs to files outside the expected document root. If files outside of the document root are not protected by "require all denied" these requests can succeed. Additionally this flaw could leak the source of interpreted files like CGI scripts.
The vulnerability can be used to execute arbitrary OS commands on the system.
Note, the vulnerability is being actively exploited in the wild.
Affected software
Amazon Linux AMI
Gentoo Linux
Arch Linux
Slackware Linux
Fedora
httpd
apache
app-admin/apache-tools
www-servers/apache
How to mitigate CVE-2021-41773
httpd - addressed in versions 2.4.50-1.fc33, 2.4.50-1.fc34, 2.4.50-1.fc35, 2.4.51-1.fc34, 2.4.51-2.fc35
apache - update to 2.4.51-1
app-admin/apache-tools - update to 2.4.54
www-servers/apache - update to 2.4.54
Links to Public Exploits and PoC-codes
- Exploit #9041 - CVE-2021-41773-EXPLOIT (A PoC exploit for CVE-2021-41773 - RCE Apache version 2.4.49/2.4.50) (May 7, 2023)
- Exploit #9024 - Apache-HTTP-Server-2.4.49-2.4.50-Path-Traversal-Remote-Code-Execution (Apache HTTP-Server 2.4.49-2.4.50 Path Traversal & Remote Code Execution PoC (CVE-2021-41773 & CVE-2021-42013)) (April 30, 2023)
- Exploit #8671 - apache-traversal (This exploit is based on a few CVE vulnerabilities affecting Apache 2.4.49. We use URL-encoded characters to access certain files or otherwise restricted resources on the server. Possible RCE on certain systems as well.) (December 15, 2022)
- Exploit #8649 - exploit-apache2-cve-2021-41773 (Exploit for path transversal vulnerability in apache) (December 6, 2022)
- Exploit #8576 - cve_2021_41773 () (November 7, 2022)
- Exploit #8568 - CVE-2021-41773 (apache路径穿越漏洞poc&exp) (November 2, 2022)
- Exploit #8567 - py-CVE-2021-41773 (python编写的apache路径穿越poc&exp) (November 2, 2022)
- Exploit #8464 - CVE-2021-41773 (Apache 2.4.49 & 2.4.50 Path Traversal to RCE exploit) (October 12, 2022)
- Exploit #8417 - CVE-2021-41773 (Apache 2.4.49 & 2.4.50 Path Traversal to RCE exploit) (September 30, 2022)
- Exploit #8216 - CVE-2021-41773 (CVE-2021-41773 Gaurav Raj's exploit modified by Plunder) (August 5, 2022)
- Exploit #8053 - CVE-2021-41773-Apache-RCE (A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outsi (June 19, 2022)
- Exploit #7985 - CVE-2021-41773 (CVE-2021-41773 | Apache HTTP Server 2.4.49 is vulnerable to Path Traversal and Remote Code execution attacks ) (June 8, 2022)
- Exploit #7611 - Path-traversal-RCE-Apache-2.4.49-2.4.50-Exploit (CVE-2021-41773 | CVE-2021-42013 Exploit Tool (Apache/2.4.49-2.4.50)) (April 7, 2022)
- Exploit #7601 - Exploit-for-path-traversal-attack-and-RCE-in-Apache-2.4.49---2.4.50 (CVE-2021-41773 | CVE-2021-42013 Exploiter Tool) (April 5, 2022)
- Exploit #7492 - CVE-2021-41773 (Apache2 2.4.49 - LFI & RCE Exploit - CVE-2021-41773) (March 15, 2022)
- Exploit #7483 - CVE-2021-41773 (Exploitation of CVE-2021-41773 a Directory Traversal in Apache 2.4.49.) (March 14, 2022)
- Exploit #7239 - CVE-2021-41773-exploiter (School project - Please use other repos for actual testing) (January 13, 2022)
- Exploit #7173 - MASS_CVE-2021-41773 () (December 15, 2021)
- Exploit #7053 - Apache HTTP Server 2.4.49 - Path Traversal & Remote Code Execution (RCE) (November 25, 2021)
- Exploit #7042 - Apache HTTP Server 2.4.50 - Remote Code Execution (RCE) (3) (November 25, 2021)
- Exploit #6926 - Apache 2.4.49/2.4.50 Traversal RCE scanner (October 22, 2021)
- Exploit #6924 - Apache 2.4.49/2.4.50 Traversal RCE (October 22, 2021)
- Exploit #6921 - CVE-2021-41773 () (October 22, 2021)
- Exploit #6916 - CVE-2021-41773 () (October 22, 2021)
- Exploit #6868 - CVE-2021-41773 (Apache 2.4.49 Path Traversal Vulnerability Checker ) (October 11, 2021)
- Exploit #6867 - CVE-2021-41773-42013 () (October 11, 2021)
- Exploit #6866 - CVE-2021-41773_CVE-2021-42013 (Apache HTTP Server 2.4.49, 2.4.50 - Path Traversal & RCE) (October 11, 2021)
- Exploit #6863 - cve-2021-41773-and-cve-2021-42013 (cve-2021-41773 即 cve-2021-42013 批量检测脚本) (October 11, 2021)
- Exploit #6861 - CVE-2021-41773-exploit (CVE-2021-41773, poc, exploit) (October 8, 2021)
- Exploit #6860 - CVE-2021-41773 (Exploit for Apache 2.4.49) (October 8, 2021)
- Exploit #6858 - CVE-2021-41773 (This is a simple POC for Apache/2.4.49 Path Traversal Vulnerability) (October 8, 2021)
- Exploit #6857 - CVE-2021-41773 (POC) (October 8, 2021)
- Exploit #6856 - CVE-2021-41773 (Fast python tool to test apache path traversal CVE-2021-41773 in a List of url ) (October 8, 2021)
- Exploit #6855 - CVE-2021-41773 (Mass exploitation CVE-2021-41773 and auto detect possible RCE) (October 8, 2021)
- Exploit #6854 - scarce-apache2 (A framework for bug hunting or pentesting targeting websites that have CVE-2021-41773 Vulnerability in public ) (October 8, 2021)
- Exploit #6852 - Simple-CVE-2021-41773-checker (Simple script realizado en bash, para revisión de múltiples hosts para CVE-2021-41773 (Apache)) (October 7, 2021)
- Exploit #6851 - mass_cve-2021-41773 (MASS CVE-2021-41773) (October 7, 2021)
- Exploit #6850 - CVE-2021-41773-RCE () (October 7, 2021)
- Exploit #6849 - CVE-2021-41773 (exploit to CVE-2021-41773) (October 7, 2021)
- Exploit #6846 - Poc-CVE-2021-41773 () (October 7, 2021)
- Exploit #6845 - CVE-2021-41773 (Apache 2.4.49) (October 7, 2021)
- Exploit #6843 - apache_normalize_path (Metasploit-Framework modules (scanner and exploit) for the CVE-2021-41773 and CVE-2021-42013 (Path Traversal in Apache 2.4.49/2.4.50)) (October 6, 2021)
- Exploit #6841 - POC-CVE-2021-41773 (Poc.py ) (October 6, 2021)
- Exploit #6840 - CVE-2021-41773-POC (CVE-2021-41773) (October 6, 2021)
- Exploit #6839 - cve-2021-41773 () (October 6, 2021)
- Exploit #6838 - CVE-2021-41773 (CVE-2021-41773 的复现) (October 6, 2021)
- Exploit #6837 - CVE-2021-41773 () (October 6, 2021)
- Exploit #6836 - cve-2021-41773 (CVE-2021-41773 Path Traversal vulnerability in Apache 2.4.49.) (October 6, 2021)
- Exploit #6835 - CVE-2021-41773 (Apache HTTP Server 2.4.49 - Path Traversal & RCE) (October 6, 2021)
- Exploit #6834 - CVE-2021-41773 (CVE-2021-41773 playground) (October 6, 2021)
- Exploit #6832 - CVE-2021-41773 () (October 6, 2021)
- Exploit #6831 - CVE-2021-41773 (Path Traversal vulnerability in Apache 2.4.49) (October 6, 2021)
- Exploit #6830 - CVE- (Docker PoC for CVE-2022-22965 with Spring Boot version 2.6.5) (October 6, 2021)
- Exploit #6829 - CVE-2021-41773-PoC (PoC for CVE-2021-41773 with docker to demonstrate) (October 6, 2021)
- Exploit #6828 - cve-2021-41773-nse (CVE-2021-41773.nse) (October 6, 2021)
- Exploit #6827 - CVE-2021-41773 (PoC CVE-2021-41773) (October 6, 2021)
- Exploit #6826 - CVE-2021-41773 (CVE-2021-41773) (October 6, 2021)
- Exploit #6824 - CVE-2021-41773 (Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49 (CVE-2021-41773)) (October 6, 2021)
- Exploit #6823 - CVE-2021-41773 () (October 6, 2021)
- Exploit #6822 - CVE-2021-41773 (Vulnerable docker images for CVE-2021-41773) (October 6, 2021)
- Exploit #6821 - CVE-2021-41773 () (October 6, 2021)
- Exploit #6820 - PoC-CVE-2021-41773 () (October 6, 2021)
- Exploit #6819 - CVE-2021-41773-PoC () (October 6, 2021)
- Exploit #6816 - PoC for path traversal in Apache HTTP Server 2.4.49 (CVE-2021-41773) (October 5, 2021)
External References
Related Security Bulletins
- Multiple vulnerabilities in Apache HTTP Server
- Slackware Linux update for httpd
- Slackware Linux update for httpd
- Amazon Linux AMI update for httpd24
- Gentoo update for Apache HTTPD
- Arch Linux update for apache
- Fedora 33 update for httpd
- Fedora 35 update for httpd
- Fedora 34 update for httpd
- Fedora 34 update for httpd
- Fedora 35 update for httpd