critical CVSS 10 Actively exploited Public exploit available

CVE-2021-41773·Apache vulnerability

A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directories are not protected by the usual default configuration "require all denied", these requests can succeed. If CGI scripts are also enabled for these aliased pathes, this could allow for remote code execution. This issue is known to be exploited in the wild. This issue only affects Apache 2.4.49 and not earlier versions. The fix in Apache HTTP Server 2.4.50 was found to be incomplete, see CVE-2021-42013.

Severity
critical
Software
Apache
Fixed in
2.4.50-1
Published
2021-10-05

Affected versions

Until: 2.4.50-1

Fixed in: 2.4.50-1

How to fix this CVE

Upgrade Apache HTTP Server to version 2.4.50-1 or later immediately, as CVE-2021-41773 allows attackers to bypass directory restrictions and potentially execute arbitrary code through path traversal. Verify that all Alias and AliasMatch directives are properly configured with restrictive access controls. After patching, restart the Apache service and validate that CGI execution is disabled for aliased paths that do not require it.

sudo dnf update httpd && sudo systemctl restart httpd

Defensia detects this vulnerability

What an exploitation attempt looks like

Sample log line indicative of exploitation attempts:

GET|POST request containing encoded or literal path traversal sequences (../, ..\, %2e%2e%2f, %2e%2e%5c) targeting aliased directories, followed by access to files outside the configured alias scope (e.g., /cgi-bin/../../etc/passwd or /icons/..%5c..%5cwindows%5csystem32%5cconfig%5csam)

WAF mitigation (if patching is not yet possible)

Add this rule to your WAF to block exploitation attempts while you schedule the patch.

Implement WAF rules to block HTTP requests containing path traversal patterns: reject requests with ../, %2e%2e, backslash sequences, and double-encoded variants in the URL path. Specifically block access to Alias-mapped URIs that contain traversal characters. Additionally, enforce a default deny policy on all paths outside explicitly allowed directories.

How to check if you are affected

  1. Check installed Apache version: apache2ctl -v or httpd -v — confirm version is 2.4.49 or lower
  2. List all Alias directives: grep -r 'Alias' /etc/apache2/sites-enabled/ or grep -r 'Alias' /etc/httpd/conf.d/ — identify paths that may be traversable
  3. Search logs for path traversal attempts: grep -i '\.\./' /var/log/apache2/access.log* or /var/log/httpd/access_log* — look for encoded variations like %2e%2e%2f or ..%5c
  4. Verify patch installation: apt list --installed | grep apache2 or rpm -q httpd — confirm version is 2.4.50-1 or higher

Indicators of compromise

  • GET requests to /cgi-bin/ with ../ or ..%5c sequences
  • POST/GET requests encoding ../ as %2e%2e%2f or %252e%252e%252f
  • Access attempts to sensitive files (passwd, shadow, config) through aliased paths
  • CGI script execution patterns originating from traversed directory paths

FAQ

What is CVE-2021-41773?

CVE-2021-41773 is a critical path traversal vulnerability in Apache 2.4.49 that allows unauthenticated attackers to escape directory restrictions configured by Alias directives and access files outside intended scope, potentially enabling remote code execution if CGI is enabled on those paths.

Is CVE-2021-41773 being actively exploited?

Yes, this vulnerability is actively exploited in the wild and is listed in the CISA Known Exploited Vulnerabilities catalog with publicly available working exploits.

What versions of Apache are affected by CVE-2021-41773?

Only Apache HTTP Server 2.4.49 is vulnerable; earlier versions are not affected. Version 2.4.50 initially appeared to fix it but contained an incomplete patch (see CVE-2021-42013), so upgrade to 2.4.50-1 or later.

How do I check if my server is vulnerable to CVE-2021-41773?

Run 'apache2ctl -v' or 'httpd -v' and look for version 2.4.49; if displayed, your server is vulnerable. Also check for Alias directives using 'grep Alias /etc/apache2/sites-enabled/* | /etc/httpd/conf.d/*'.

Does Defensia detect CVE-2021-41773?

Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If Apache is installed on a monitored server, CVE-2021-41773 will appear in your dashboard with remediation steps.

Related Apache CVEs

CVE-2021-42013CVSS 10It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directories are not protected by the usual default configuration "require all denied", these requests can succeed. If CGI scripts are also enabled for these aliased pathes, this could allow for remote code execution. This issue only affects Apache 2.4.49 and Apache 2.4.50 and not earlier versions.
CVE-2026-59797CVSS 9.8Improper Privilege Management vulnerability in Apache HTTP Server's mod_ssl via SSLRequire and file-related expressions. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
CVE-2024-38476CVSS 9.8Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend applications whose response headers are malicious or exploitable. Users are recommended to upgrade to version 2.4.60, which fixes this issue.
CVE-2024-38474CVSS 9.8Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker to execute scripts in directories permitted by the configuration but not directly reachable by any URL or source disclosure of scripts meant to only to be executed as CGI. Users are recommended to upgrade to version 2.4.60, which fixes this issue. Some RewriteRules that capture and substitute unsafely will now fail unless rewrite flag "UnsafeAllow3F" is specified.
CVE-2026-57941CVSS 9.8Use After Free vulnerability in Apache HTTP Server's mod_http2 via shared session->bbtmp re-entrancy This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.

References

Track CVEs across your fleet automatically

Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2021-41773. Free for 1 server.

Get started free