Vulnerability Details
Basic Information
| Title | CVE-2021-42013: Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773) |
|---|---|
| Type | attackerkb |
| Published | 2025-05-04T00:00:00 |
| Last Seen | 2025-05-04T18:46:00 |
| CVSS Score | 9.8 (CRITICAL) |
CVSS v3 Details
| Attack Vector | NETWORK |
|---|---|
| Attack Complexity | LOW |
| Privileges Required | NONE |
| User Interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality Impact | HIGH |
| Integrity Impact | HIGH |
| Availability Impact | HIGH |
CVE Information
| CVE IDs | CVE-2021-41773, CVE-2021-42013 |
|---|---|
| CWE | |
| Bulletin Family | info |
Description
It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of…
Impact Assessment
| Base Score | 9.8 |
|---|---|
| Severity | CRITICAL |