Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100Vexday Risk Score
Corrige ahora. Ella está bajo explotación confirmada por CISA y tiene exploit funcional público.
ssvc Actcvss 9.8epss 100%
de la publicación al arma0 días
Publicada en NVD7 oct
1ª PoC7 oct
metasploit10 may
CISA KEV+27d
probabilidad de explotación
100%top 1% de las CVE
explotación observada
síCISA + VulnCheck
73 exploit(s) público(s)
Acción exigida por CISAplazo federal: 2021-11-17
Apply updates per vendor instructions.
Investigado y redactado con IA a partir del advisory del fabricante y análisis públicos, con las fuentes citadas. Verifica siempre la versión corregida en el advisory oficial antes de actuar.
It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directories are not protected by the usual default configuration "require all denied", these requests can succeed. If CGI scripts are also enabled for these aliased pathes, this could allow for remote code execution. This issue only affects Apache 2.4.49 and Apache 2.4.50 and not earlier versions.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Productos afectados
Apache Software Foundation · Apache HTTP ServerPoCs públicas encontradas — 73✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/50512exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/50406exploitdbwww.exploit-db.com/exploits/50446no verificadogithubgithub.com/walnutsecurity/cve-2021-42013★ 27githubgithub.com/Vulnmachines/cve-2021-42013★ 15githubgithub.com/asaotomo/CVE-2021-42013-Apache-RCE-Poc-Exp★ 10githubgithub.com/andrea-mattioli/apache-exploit-CVE-2021-42013★ 9githubgithub.com/K3ysTr0K3R/CVE-2021-42013-EXPLOIT★ 7githubgithub.com/TheLastVvV/CVE-2021-42013_Reverse-Shell★ 7githubgithub.com/BassoNicolas/CVE-2021-42013★ 3githubgithub.com/twseptian/cve-2021-42013-docker-lab★ 2githubgithub.com/TheLastVvV/CVE-2021-42013★ 2githubgithub.com/bananoname/cve-2021-42013★ 1githubgithub.com/Hamesawian/CVE-2021-42013★ 1githubgithub.com/jas9reet/CVE-2021-42013-LAB★ 1githubgithub.com/cybfar/cve-2021-42013-httpd★ 1githubgithub.com/robotsense1337/CVE-2021-42013★ 1githubgithub.com/drackyjr/CVE-2021-42013★ 1githubgithub.com/vudala/CVE-2021-42013★ 1githubgithub.com/asepsaepdin/CVE-2021-42013★ 0githubgithub.com/Makavellik/POC-CVE-2021-42013-EXPLOIT★ 0githubgithub.com/FakhriCRD/Apache-CVE-2021-42013-RCE-Exploit★ 0githubgithub.com/ranasen-rat/cve-2021-42013★ 0githubgithub.com/zeynepglygt/apache-cve-2021-42013-rce★ 0githubgithub.com/Joapath/CVE-2021-42013★ 0githubgithub.com/eunho87/CVE-2021-42013★ 0githubgithub.com/berraesen/apache-cve-2021-42013-lab★ 0githubgithub.com/LayarKacaSiber/CVE-2021-42013★ 0githubgithub.com/viliuspovilaika/cve-2021-42013★ 0githubgithub.com/hadrian3689/apache_2.4.50★ 0githubgithub.com/mightysai1997/cve-2021-42013★ 0githubgithub.com/mightysai1997/cve-2021-42013L★ 0githubgithub.com/mightysai1997/cve-2021-42013.get★ 0githubgithub.com/12345qwert123456/CVE-2021-42013★ 0githubgithub.com/xMohamed0/CVE-2021-42013-ApacheRCE★ 0githubgithub.com/dream434/cve-2021-42013-apache★ 0vulncheckvulncheck.com/xdb/94a8be0205aeno verificadovulncheckvulncheck.com/xdb/1cfa52b1622bno verificadovulncheckvulncheck.com/xdb/4c0e3155c6deno verificadovulncheckvulncheck.com/xdb/9db94a24977cno verificadocve_referencepacketstormsecurity.com/files/164501/Apache-HTTP-Server-2.4.50-Path-Traversal-Code-Execution.htmlno verificadocve_referencepacketstormsecurity.com/files/164609/Apache-HTTP-Server-2.4.50-Remote-Code-Execution.htmlno verificadocve_referencepacketstormsecurity.com/files/164629/Apache-2.4.49-2.4.50-Traversal-Remote-Code-Execution.htmlno verificadocve_referencepacketstormsecurity.com/files/164941/Apache-HTTP-Server-2.4.50-Remote-Code-Execution.htmlno verificadocve_referencepacketstormsecurity.com/files/165089/Apache-HTTP-Server-2.4.50-CVE-2021-42013-Exploitation.htmlno verificadocve_referencepacketstormsecurity.com/files/167397/Apache-2.4.50-Remote-Code-Execution.htmlno verificadovulncheckvulncheck.com/xdb/05376c442191no verificadovulncheckvulncheck.com/xdb/80019b8370afno verificadovulncheckvulncheck.com/xdb/cc14508a170cno verificadovulncheckvulncheck.com/xdb/1164c6167307no verificadovulncheckvulncheck.com/xdb/4bad25e994e2no verificadovulncheckvulncheck.com/xdb/5ca2b55d2782no verificadovulncheckvulncheck.com/xdb/f480a19ee326no verificadovulncheckvulncheck.com/xdb/7f1b705bcf83no verificadovulncheckvulncheck.com/xdb/28d7e8231b1fno verificadovulncheckvulncheck.com/xdb/7ff49021c22eno verificadovulncheckvulncheck.com/xdb/f7ab4f8db55bno verificadovulncheckvulncheck.com/xdb/b07b7850bf05no verificadovulncheckvulncheck.com/xdb/ef11e24302d0no verificadovulncheckvulncheck.com/xdb/bfc30889d329no verificadovulncheckvulncheck.com/xdb/5e64583b49f2no verificadovulncheckvulncheck.com/xdb/b1d2ff60b684no verificadovulncheckvulncheck.com/xdb/6fea2c044e7ano verificadovulncheckvulncheck.com/xdb/1049bafbb722no verificadovulncheckvulncheck.com/xdb/93027facc9f9no verificadovulncheckvulncheck.com/xdb/56bd1b4d31bbno verificadovulncheckvulncheck.com/xdb/e543e9003746no verificadovulncheckvulncheck.com/xdb/c9583159535cno verificadovulncheckvulncheck.com/xdb/e7a565f8ed42no verificadovulncheckvulncheck.com/xdb/e3d6c5260840no verificadovulncheckvulncheck.com/xdb/699d0a790bc9no verificadovulncheckvulncheck.com/xdb/dd76d0d27f2ano verificadovulncheckvulncheck.com/xdb/b892ed4cf747no verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
Referencias
http://jvn.jp/en/jp/JVN51106450/index.htmlhttp://packetstormsecurity.com/files/164501/Apache-HTTP-Server-2.4.50-Path-Traversal-Code-Execution.htmlhttp://packetstormsecurity.com/files/164609/Apache-HTTP-Server-2.4.50-Remote-Code-Execution.htmlhttp://packetstormsecurity.com/files/164629/Apache-2.4.49-2.4.50-Traversal-Remote-Code-Execution.htmlhttp://packetstormsecurity.com/files/164941/Apache-HTTP-Server-2.4.50-Remote-Code-Execution.htmlhttp://packetstormsecurity.com/files/165089/Apache-HTTP-Server-2.4.50-CVE-2021-42013-Exploitation.htmlhttp://packetstormsecurity.com/files/167397/Apache-2.4.50-Remote-Code-Execution.htmlhttps://httpd.apache.org/security/vulnerabilities_24.htmlhttps://lists.apache.org/thread.html/r17a4c6ce9aff662efd9459e9d1850ab4a611cb23392fc68264c72cb3%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r7c795cd45a3384d4d27e57618a215b0ed19cb6ca8eb070061ad5d837%40%3Cannounce.apache.org%3Ehttps://lists.apache.org/thread.html/rb5b0e46f179f60b0c70204656bc52fcb558e961cb4d06a971e9e3efb%40%3Cusers.httpd.apache.org%3Ehttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RMIIEFINL6FUIOPD2A3M5XC6DH45Y3CC/