OS Command Injection in Apache HTTP Server - CVE-2021-42013
Published: October 7, 2021 / Updated: April 30, 2023
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.
The vulnerability exists due to insufficient fix for the path traversal vulnerability #VU57063 (CVE-2021-41733). A remote unauthenticated attacker can send a specially crafted HTTP request to the affected server and execute arbitrary OS commands on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Arch Linux
Amazon Linux AMI
Gentoo Linux
Slackware Linux
Fedora
JD Edwards EnterpriseOne Tools
httpd
apache
app-admin/apache-tools
www-servers/apache
How to mitigate CVE-2021-42013
JD Edwards EnterpriseOne Tools - update to 9.2.6.0
httpd - addressed in versions 2.4.50-1.fc33, 2.4.50-1.fc34, 2.4.50-1.fc35, 2.4.51-1.fc34, 2.4.51-2.fc35
apache - update to 2.4.51-1
app-admin/apache-tools - update to 2.4.54
www-servers/apache - update to 2.4.54
Links to Public Exploits and PoC-codes
- Exploit #9023 - Apache-HTTP-Server-2.4.49-2.4.50-Path-Traversal-Remote-Code-Execution (Apache HTTP-Server 2.4.49-2.4.50 Path Traversal & Remote Code Execution PoC (CVE-2021-41773 & CVE-2021-42013)) (April 30, 2023)
- Exploit #8670 - apache-traversal (This exploit is based on a few CVE vulnerabilities affecting Apache 2.4.49. We use URL-encoded characters to access certain files or otherwise restricted resources on the server. Possible RCE on certain systems as well.) (December 15, 2022)
- Exploit #8416 - CVE-2021-41773 (Apache 2.4.49 & 2.4.50 Path Traversal to RCE exploit) (September 30, 2022)
- Exploit #8188 - CVE-2021-42013 (Apache 2.4.49-50 Remote Code Execution Exploit) (July 28, 2022)
- Exploit #8187 - CVE-2021-42013 (Apache 2.4.49-50 Remote Code Execution Exploit) (July 28, 2022)
- Exploit #7927 - cve-2021-42013 (Exploit for Apache 2.4.50 (CVE-2021-42013)) (May 31, 2022)
- Exploit #7610 - Path-traversal-RCE-Apache-2.4.49-2.4.50-Exploit (CVE-2021-41773 | CVE-2021-42013 Exploit Tool (Apache/2.4.49-2.4.50)) (April 7, 2022)
- Exploit #7602 - Exploit-for-path-traversal-attack-and-RCE-in-Apache-2.4.49---2.4.50 (CVE-2021-41773 | CVE-2021-42013 Exploiter Tool) (April 5, 2022)
- Exploit #7203 - CVE-2021-42013-Apache-RCE-Poc-Exp (Apache 远程代码执行 (CVE-2021-42013)批量检测工具:Apache HTTP Server是美国阿帕奇(Apache)基金会的一款开源网页服务器。该服务器具有快速、可靠且可通过简单的API进行扩充的特点,发现 Apache HTTP Server 2.4.50 中针对 CVE-2021-41773 的修复不够充分。攻击者可以使用路径遍历攻击将 URL 映射到由类似别名的指令配置的目录之外的文件。如果这些目录之外的文件 (December 26, 2021)
- Exploit #7041 - Apache HTTP Server 2.4.50 - Remote Code Execution (RCE) (3) (November 25, 2021)
- Exploit #7051 - Apache HTTP Server 2.4.50 - Path Traversal & Remote Code Execution (RCE) (November 25, 2021)
- Exploit #7046 - Apache HTTP Server 2.4.50 - Remote Code Execution (RCE) (2) (November 25, 2021)
- Exploit #7025 - CVE-2021-42013-ApacheRCE () (November 16, 2021)
- Exploit #6979 - CVE-2021-42013 (Exploit Apache 2.4.50(CVE-2021-42013)) (November 3, 2021)
- Exploit #6947 - cve-2021-42013 (cve-2021-42013.py is a python script that will help in finding Path Traversal or Remote Code Execution vulnerability in Apache 2.4.50) (October 27, 2021)
- Exploit #6931 - CVE-2021-42013 (Poc CVE-2021-42013 - Apache 2.4.50 without CGI) (October 24, 2021)
- Exploit #6925 - Apache 2.4.49/2.4.50 Traversal RCE scanner (October 22, 2021)
- Exploit #6923 - Apache 2.4.49/2.4.50 Traversal RCE (October 22, 2021)
- Exploit #6915 - CVE-2021-42013 () (October 22, 2021)
- Exploit #6865 - CVE-2021-41773_CVE-2021-42013 (Apache HTTP Server 2.4.49, 2.4.50 - Path Traversal & RCE) (October 11, 2021)
- Exploit #6864 - cve-2021-41773-and-cve-2021-42013 (cve-2021-41773 即 cve-2021-42013 批量检测脚本) (October 11, 2021)
- Exploit #6859 - cve-2021-42013 (Apache 2.4.50 Path traversal vulnerability) (October 8, 2021)
- Exploit #6848 - apache-exploit-CVE-2021-42013 (Exploit with integrated shodan search) (October 7, 2021)
External References
Related Security Bulletins
- Remote code execution in Apache HTTP Server
- Slackware Linux update for httpd
- Amazon Linux AMI update for httpd24
- Multiple vulnerabilities in JD Edwards EnterpriseOne Tools
- Gentoo update for Apache HTTPD
- Arch Linux update for apache
- Fedora 33 update for httpd
- Fedora 35 update for httpd
- Fedora 34 update for httpd
- Fedora 34 update for httpd
- Fedora 35 update for httpd