CVE-2021-42013·Apache vulnerability
It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directories are not protected by the usual default configuration "require all denied", these requests can succeed. If CGI scripts are also enabled for these aliased pathes, this could allow for remote code execution. This issue only affects Apache 2.4.49 and Apache 2.4.50 and not earlier versions.
- Severity
- critical
- Software
- Apache
- Fixed in
- 2.4.51-1
- Published
- 2021-10-07
Affected versions
Until: 2.4.51-1
Fixed in: 2.4.51-1
How to fix this CVE
Immediately upgrade Apache HTTP Server to version 2.4.51 or later to patch the incomplete fix from the previous release. This vulnerability allows attackers to bypass directory restrictions and potentially execute arbitrary code through CGI scripts. Verify your current version and apply the update through your distribution's package manager without delay, as active exploitation is documented in the wild.
sudo dnf update httpdDefensia detects this vulnerability
What an exploitation attempt looks like
Sample log line indicative of exploitation attempts:
POST|GET /.*\.\./ HTTP/|GET /.*%2e%2e%2f HTTP/|GET /.*%252e%252e%252f HTTP/|accessing files outside configured Alias paths with traversal sequencesWAF mitigation (if patching is not yet possible)
Add this rule to your WAF to block exploitation attempts while you schedule the patch.
Implement URL rewrite rules to block requests containing path traversal sequences (../ or %2e%2e%2f encoded variants) before they reach the backend Apache server; enforce 'require all denied' as default for all non-aliased directories; disable CGI execution in aliased paths if not explicitly required.How to check if you are affected
- Run 'apache2ctl -v' or 'httpd -v' to check the installed Apache version; versions 2.4.49 and 2.4.50 are vulnerable
- Examine your Apache configuration with 'apache2ctl -S' or 'httpd -S' to identify Alias directives and verify CGI is not enabled for aliased paths
- Search Apache access logs for suspicious path traversal patterns using: grep -E '\.\./' /var/log/apache2/access.log*
- Verify the patch with 'apache2ctl -v' after update; confirm version is 2.4.51 or later and restart Apache with 'sudo systemctl restart apache2'
Indicators of compromise
- HTTP requests with ../ or URL-encoded variants (../, %2e%2e%2f, %252e%252e%252f) in the path
- Access logs showing requests to files outside configured Alias directories
- Apache error logs with file access denied errors followed by successful CGI execution attempts
FAQ
What is CVE-2021-42013?
This vulnerability is a path traversal flaw that allows unauthenticated attackers to access files outside Apache's configured alias directories by exploiting an incomplete security patch from version 2.4.50, potentially enabling remote code execution if CGI scripts are enabled.
Is CVE-2021-42013 being actively exploited?
Yes, CVE-2021-42013 is listed in the CISA Known Exploited Vulnerabilities catalog and public exploits are available on Exploit-DB, making it a critical priority for immediate patching.
What versions of Apache are affected by CVE-2021-42013?
Only Apache HTTP Server versions 2.4.49 and 2.4.50 are vulnerable; earlier versions are unaffected, and the vulnerability is fixed in version 2.4.51 and later.
How do I check if my server is vulnerable to CVE-2021-42013?
Run 'apache2ctl -v' or 'httpd -v' and check if the version output shows 2.4.49 or 2.4.50; if either is displayed, your server requires immediate patching.
Does Defensia detect CVE-2021-42013?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If Apache is installed on a monitored server, CVE-2021-42013 will appear in your dashboard with remediation steps.
Related Apache CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2021-42013. Free for 1 server.
Get started free