EXPOSURES › CVE-2021-41773
CVE-2021-41773
CRITICAL ⌖ ON CISA KEV · EXPLOITEDApache HTTP Server's path traversal vulnerability allowed remote code execution, and the initial patch was inadequate, demonstrating a failure to properly secure web server configurations and remediate vulnerabilities effectively.
A critical path traversal vulnerability (CVE-2021-41773) in Apache HTTP Server enabled remote code execution, and the initial patch proved insufficient, requiring further remediation. DIB organizations using Apache must ensure proper configuration, restrict access to sensitive files, and promptly apply all security updates, as this failure highlights a potential for significant data compromise and compliance violations (NIST 800-171 controls 3.a, 3.b, 3.c).
Shame score — The inadequate initial patch and active exploitation linked to ransomware demonstrate a significant failure in Apache's vulnerability management and remediation process, impacting a widely-used component.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by Alias-like directives are not under default �require all denied� or if CGI scripts are enabled. The original patch issued under this CVE ID is insufficient, please review remediation information under CVE-2021-42013.
"Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution... The original patch issued under this CVE ID is insufficient"