Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
Apache HTTP Server 2.4.49 has a flaw in how it processes file paths, allowing attackers to access files outside intended directories through specially crafted URLs. If those files aren't properly protected, attackers could read sensitive data or run malicious code if CGI scripts are enabled.
A path normalization bypass in Apache 2.4.49 enables directory traversal attacks to map URLs to files outside Alias-like directive scopes. The vulnerability requires files outside configured directories to lack default "require all denied" protections; exploitation can lead to information disclosure or RCE if CGI execution is permitted on aliased paths. This issue affects only version 2.4.49 and is actively exploited in the wild.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →