EXPOSURES › CVE-2021-42013
CVE-2021-42013
CRITICAL ⌖ ON CISA KEV · EXPLOITEDAn incomplete Apache HTTP Server patch left systems vulnerable to remote code execution via path traversal, actively exploited in ransomware attacks and impacting NIST 800-171 compliance efforts.
CVE-2021-42013 represents a path traversal vulnerability in Apache HTTP Server, stemming from an incomplete fix for a prior vulnerability. This allows attackers to execute code remotely, potentially leading to data breaches and system compromise, directly impacting controls like SP 800-171's Access Control and Configuration Management. DIB organizations must immediately verify patching and review configurations to prevent exploitation.
Shame score — The vulnerability's exploitation in active ransomware campaigns and the incomplete patch demonstrate a significant failure in Apache's security practices and a potential for widespread compromise.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by Alias-like directives are not under default require all denied or if CGI scripts are enabled. This CVE ID resolves an incomplete patch for CVE-2021-41773.
"Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by Alias-like directives are not under default require all denied or if CGI scripts are enabled. This CVE ID resolves an incomplete patch for CVE-2021-41773."