Skip to content
COOEY

EXPOSURES › CVE-2021-41773

CVE-2021-41773

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-41773 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 ransomwarerceexploited-in-wildunpatched

Apache HTTP Server's path traversal vulnerability allowed remote code execution, and the initial patch was inadequate, demonstrating a failure to properly secure web server configurations and remediate vulnerabilities effectively.

A critical path traversal vulnerability (CVE-2021-41773) in Apache HTTP Server enabled remote code execution, and the initial patch proved insufficient, requiring further remediation. DIB organizations using Apache must ensure proper configuration, restrict access to sensitive files, and promptly apply all security updates, as this failure highlights a potential for significant data compromise and compliance violations (NIST 800-171 controls 3.a, 3.b, 3.c).

Shame score — The inadequate initial patch and active exploitation linked to ransomware demonstrate a significant failure in Apache's vulnerability management and remediation process, impacting a widely-used component.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by Alias-like directives are not under default �require all denied� or if CGI scripts are enabled. The original patch issued under this CVE ID is insufficient, please review remediation information under CVE-2021-42013.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.60
Apache HTTP Server path traversal vulnerability allowing remote code execution is a severe security flaw, with the original patch deemed insufficient, indicating a significant failure in vendor respon
cooey ↗ severe-fallout -0.80
Severe vulnerability with insufficient initial patch, indicating a significant security failure.
"Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution... The original patch issued under this CVE ID is insufficient"
app.opencve.io ↗ severe-fallout +0.00
No specific sentiment toward Apache; generic CVE listing page.
www.cvefind.com ↗ severe-fallout +0.00
No specific sentiment toward Apache; generic CVE database page.
cve.akaoma.com ↗ severe-fallout +0.00
No specific sentiment toward Apache; generic CVE listing page.
SentinelOne ↗ severe-fallout +0.00
No specific sentiment toward Apache; unrelated vendor page.
fortiguard.fortinet.com ↗ severe-fallout +0.00
No specific sentiment toward Apache; unrelated vendor page.
sam.gov ↗ severe-fallout +0.00
No specific sentiment toward Apache; unrelated government page.
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.