Skip to content
COOEY

EXPOSURES › CVE-2021-42013

CVE-2021-42013

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-42013 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 ransomwarerceexploited-in-wildunpatched

An incomplete Apache HTTP Server patch left systems vulnerable to remote code execution via path traversal, actively exploited in ransomware attacks and impacting NIST 800-171 compliance efforts.

CVE-2021-42013 represents a path traversal vulnerability in Apache HTTP Server, stemming from an incomplete fix for a prior vulnerability. This allows attackers to execute code remotely, potentially leading to data breaches and system compromise, directly impacting controls like SP 800-171's Access Control and Configuration Management. DIB organizations must immediately verify patching and review configurations to prevent exploitation.

Shame score — The vulnerability's exploitation in active ransomware campaigns and the incomplete patch demonstrate a significant failure in Apache's security practices and a potential for widespread compromise.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by Alias-like directives are not under default require all denied or if CGI scripts are enabled. This CVE ID resolves an incomplete patch for CVE-2021-41773.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.60
Apache HTTP Server's incomplete patch for CVE-2021-41773 led to a new path traversal vulnerability allowing remote code execution, indicating a failure in timely and complete remediation.
cooey ↗ severe-fallout -0.60
Apache HTTP Server's incomplete patch for CVE-2021-41773 led to a new path traversal vulnerability allowing remote code execution, indicating a failure in timely and complete remediation.
"Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by Alias-like directives are not under default require all denied or if CGI scripts are enabled. This CVE ID resolves an incomplete patch for CVE-2021-41773."
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.