CVE-2021-41773·Apache vulnerability
A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directories are not protected by the usual default configuration "require all denied", these requests can succeed. If CGI scripts are also enabled for these aliased pathes, this could allow for remote code execution. This issue is known to be exploited in the wild. This issue only affects Apache 2.4.49 and not earlier versions. The fix in Apache HTTP Server 2.4.50 was found to be incomplete, see CVE-2021-42013.
- Severity
- critical
- Software
- Apache
- Fixed in
- 2.4.50-1
- Published
- 2021-10-05
Affected versions
Until: 2.4.50-1
Fixed in: 2.4.50-1
How to fix this CVE
Upgrade Apache HTTP Server to version 2.4.50-1 or later immediately, as CVE-2021-41773 allows attackers to bypass directory restrictions and potentially execute arbitrary code through path traversal. Verify that all Alias and AliasMatch directives are properly configured with restrictive access controls. After patching, restart the Apache service and validate that CGI execution is disabled for aliased paths that do not require it.
sudo dnf update httpd && sudo systemctl restart httpdDefensia detects this vulnerability
What an exploitation attempt looks like
Sample log line indicative of exploitation attempts:
GET|POST request containing encoded or literal path traversal sequences (../, ..\, %2e%2e%2f, %2e%2e%5c) targeting aliased directories, followed by access to files outside the configured alias scope (e.g., /cgi-bin/../../etc/passwd or /icons/..%5c..%5cwindows%5csystem32%5cconfig%5csam)WAF mitigation (if patching is not yet possible)
Add this rule to your WAF to block exploitation attempts while you schedule the patch.
Implement WAF rules to block HTTP requests containing path traversal patterns: reject requests with ../, %2e%2e, backslash sequences, and double-encoded variants in the URL path. Specifically block access to Alias-mapped URIs that contain traversal characters. Additionally, enforce a default deny policy on all paths outside explicitly allowed directories.How to check if you are affected
- Check installed Apache version: apache2ctl -v or httpd -v — confirm version is 2.4.49 or lower
- List all Alias directives: grep -r 'Alias' /etc/apache2/sites-enabled/ or grep -r 'Alias' /etc/httpd/conf.d/ — identify paths that may be traversable
- Search logs for path traversal attempts: grep -i '\.\./' /var/log/apache2/access.log* or /var/log/httpd/access_log* — look for encoded variations like %2e%2e%2f or ..%5c
- Verify patch installation: apt list --installed | grep apache2 or rpm -q httpd — confirm version is 2.4.50-1 or higher
Indicators of compromise
- GET requests to /cgi-bin/ with ../ or ..%5c sequences
- POST/GET requests encoding ../ as %2e%2e%2f or %252e%252e%252f
- Access attempts to sensitive files (passwd, shadow, config) through aliased paths
- CGI script execution patterns originating from traversed directory paths
FAQ
What is CVE-2021-41773?
CVE-2021-41773 is a critical path traversal vulnerability in Apache 2.4.49 that allows unauthenticated attackers to escape directory restrictions configured by Alias directives and access files outside intended scope, potentially enabling remote code execution if CGI is enabled on those paths.
Is CVE-2021-41773 being actively exploited?
Yes, this vulnerability is actively exploited in the wild and is listed in the CISA Known Exploited Vulnerabilities catalog with publicly available working exploits.
What versions of Apache are affected by CVE-2021-41773?
Only Apache HTTP Server 2.4.49 is vulnerable; earlier versions are not affected. Version 2.4.50 initially appeared to fix it but contained an incomplete patch (see CVE-2021-42013), so upgrade to 2.4.50-1 or later.
How do I check if my server is vulnerable to CVE-2021-41773?
Run 'apache2ctl -v' or 'httpd -v' and look for version 2.4.49; if displayed, your server is vulnerable. Also check for Alias directives using 'grep Alias /etc/apache2/sites-enabled/* | /etc/httpd/conf.d/*'.
Does Defensia detect CVE-2021-41773?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If Apache is installed on a monitored server, CVE-2021-41773 will appear in your dashboard with remediation steps.
Related Apache CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2021-41773. Free for 1 server.
Get started free