CVE-2021-42013

critical

Description

It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directories are not protected by the usual default configuration "require all denied", these requests can succeed. If CGI scripts are also enabled for these aliased pathes, this could allow for remote code execution. This issue only affects Apache 2.4.49 and Apache 2.4.50 and not earlier versions.

References

https://github.com/RenatoAntunovic/cve-metasploit-skeniranje

https://github.com/Balckers/mcp-security-server

https://github.com/Cyb3rZ3d/aws-purple-team-detection-project

https://github.com/chengbochuan3/Security-Blog

https://github.com/chengbochuan3/CVE-Apache-Ecosystem

https://github.com/Emaar1x/CVE-2021-41773

https://github.com/KunalKhandelwal-dev/cve-2021-41773-lab

https://github.com/sbimoxa/cve-2021-41773-lab

https://github.com/berraesen/apache-cve-2021-42013-lab

https://github.com/Abhigiri77/Vulnerability-CVE-Scanner

https://github.com/johnwickakash12/CVE-2021-41773

https://github.com/eunho87/CVE-2021-42013

https://github.com/korneevscp/osint-target

https://github.com/RootVandal/Netrecon

https://github.com/Ejikemeilo/CVE-Scanner

https://github.com/trainer80/Common-Vulnerabilities-and-Exposures-CVE-

https://github.com/Joapath/CVE-2021-42013

https://github.com/Joapath/CVE-2021-41773

https://github.com/MohammedAbdulAhadSaud/DotSlash

https://github.com/harshweb-cyber/Netscout

https://github.com/Guppss/VulnScan-Pro

https://github.com/aimannurzharfan/netguard-sentinel

https://github.com/aimannurzharfan/Netguard-Sentinel

https://github.com/Silence-Cy/ModuScan

https://github.com/aadov/vuln-management-lab

https://github.com/krish-achanta/vuln-validator

https://github.com/youssefelnamer/scanner

https://github.com/zeemanmemon/cve-lookup

https://github.com/bytezora/recon-x

https://github.com/mrjoker-web/ShadowCVE

https://github.com/Retr0wq/network-scanner

https://github.com/scorpiocodex/vulnix

https://github.com/neeljain21/network-security-scanner

https://github.com/Sombra-1/vulnmind

https://github.com/0xBugatti/AwesomeNmap

https://github.com/AbdulMoiz6692/cve-vulnerability-scanner-pro

https://github.com/RehmanAjaz/CVE-Scanner

https://github.com/zeynepglygt/apache-cve-2021-42013-rce

https://github.com/CVE-ORG/CVE-ORG

https://github.com/sudo-boma/vulnerability-scanner

https://github.com/drackyjr/CVE-2021-42013

https://github.com/FakhriCRD/Apache-CVE-2021-42013-RCE-Exploit

https://github.com/vBarbaros/security-faux-pas

https://github.com/alpaykuzu/PortScanner-CVE-Tool

https://github.com/odaysec/PwnTraverse

https://github.com/Makavellik/POC-CVE-2021-42013-EXPLOIT

https://github.com/hackedrishi/CTF_WRITEUPS-TryHackMe-CVE-2021-41773-

https://github.com/AnonUsenix/LLM_Agent_Cybersecurity_Forensic

https://github.com/roman-sachenko/app-security-cve-vulns

https://github.com/HariCyber-Sec/hackviser-cve-labs

https://github.com/r0otk3r/CVE-2021-41773

https://github.com/yigitcantunay35/Reconx

https://github.com/r1skkam/CVE-Common-Vulnerabilities-and-Exposures

https://github.com/psibot/apache-vulnerable

https://github.com/Ask-os/CVE-2021-41773

https://github.com/sakshiishukla/Python-Vulnerability-Scanner

https://github.com/Urbank-61/Urbank-61-CSC180CVEProject

https://github.com/MagicGautam/CVEs-Proof-Of-Concept

https://github.com/g1san/Agents-for-Vulnerable-Dockers-and-related-Benchmarks

https://github.com/vux125/cve

https://github.com/macEar/cve-playground

https://github.com/Vanshuk-Bhagat/Apache-HTTP-Server-Vulnerabilities-CVE-2021-41773-and-CVE-2021-42013

https://github.com/hungnqdz/cve

https://github.com/ucsb-seclab/CVEX-records

https://github.com/Jhonsonwannaa/cve-2021-42013-apache

https://github.com/rafifdna/CVE-2021-42013

https://github.com/BassoNicolas/CVE-2021-42013

https://github.com/OpenCVEs/CVE-2021-41773

https://github.com/OfriOuzan/CVE-2021-41773_CVE-2021-42013_Exploits

https://github.com/vudala/CVE-2021-42013

https://github.com/0xGabe/Apache-CVEs

https://github.com/heane404/CVE_scan

https://github.com/Zeyad-Azima/Remedy4me

https://github.com/blackn0te/Apache-HTTP-Server-2.4.49-2.4.50-Path-Traversal-Remote-Code-Execution

https://github.com/randomAnalyst/PoC-Fetcher

https://github.com/pwn3z/CVE-2021-41773-Apache-RCE

https://github.com/viliuspovilaika/cve-2021-42013

https://github.com/wangfly-me/Apache_Penetration_Tool

https://github.com/hadrian3689/apache_2.4.50

https://github.com/CalfCrusher/Path-traversal-RCE-Apache-2.4.49-2.4.50-Exploit

https://github.com/azazelm3dj3d/apache-traversal

https://github.com/mauricelambert/CVE-2021-42013

https://github.com/tangxiaofeng7/CVE-2022-22947-Spring-Cloud-Gateway

https://github.com/rnsss/CVE-2021-42013

https://github.com/asaotomo/CVE-2021-42013-Apache-RCE-Poc-Exp

https://securitylab.github.com/research/fuzzing-apache-3/

https://github.com/IcmpOff/Apache-2.4.49-2.4.50-Traversal-Remote-Code-Execution-Exploit

https://github.com/Hydragyrum/CVE-2021-41773-Playground

https://github.com/robotsense1337/CVE-2021-42013

https://github.com/vulf/CVE-2021-41773_42013

https://github.com/theLSA/apache-httpd-path-traversal-checker

https://github.com/twseptian/cve-2021-42013-docker-lab

https://github.com/twseptian/CVE-2021-42013-Docker-Lab

https://github.com/MrCl0wnLab/SimplesApachePathTraversal

https://github.com/ksanchezcld/httpd-2.4.49

https://github.com/inbug-team/CVE-2021-41773_CVE-2021-42013

https://github.com/corelight/CVE-2021-41773

https://github.com/Zeop-CyberSec/apache_normalize_path

https://github.com/jaychen2/NIST-BULK-CVE-Lookup

https://www.povilaika.com/apache-2-4-50-exploit/

https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-42013

https://lists.apache.org/thread.html/rb5b0e46f179f60b0c70204656bc52fcb558e961cb4d06a971e9e3efb%40%3Cusers.httpd.apache.org%3E

https://lists.apache.org/thread.html/r7c795cd45a3384d4d27e57618a215b0ed19cb6ca8eb070061ad5d837%40%3Cannounce.apache.org%3E

https://lists.apache.org/thread.html/r17a4c6ce9aff662efd9459e9d1850ab4a611cb23392fc68264c72cb3%40%3Ccvs.httpd.apache.org%3E

https://httpd.apache.org/security/vulnerabilities_24.html

http://packetstormsecurity.com/files/167397/Apache-2.4.50-Remote-Code-Execution.html

http://packetstormsecurity.com/files/164941/Apache-HTTP-Server-2.4.50-Remote-Code-Execution.html

http://packetstormsecurity.com/files/164629/Apache-2.4.49-2.4.50-Traversal-Remote-Code-Execution.html

http://packetstormsecurity.com/files/164609/Apache-HTTP-Server-2.4.50-Remote-Code-Execution.html

http://packetstormsecurity.com/files/164501/Apache-HTTP-Server-2.4.50-Path-Traversal-Code-Execution.html

Details

Source: Mitre, NVD

Published: 2021-10-07

Updated: 2026-06-17

Known Exploited Vulnerability (KEV)

Risk Information

CVSS v2

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Severity: High

CVSS v3

Base Score: 9.8

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical

EPSS

EPSS: 0.99964