Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100Vexday Risk Score
Corrija agora. Ela está sob exploração confirmada pelo CISA e tem exploit funcional público.
ssvc Actcvss 9.8epss 100%
da publicação à arma0 dias
Publicada no NVD7 de out.
1ª PoC7 de out.
metasploit10 de mai.
CISA KEV+27d
probabilidade de exploração
100%top 1% das CVEs
exploração observada
simCISA + VulnCheck
73 exploit(s) público(s)
Ação exigida pela CISAprazo federal: 2021-11-17
Apply updates per vendor instructions.
Pesquisado e redigido com IA a partir do advisory do fornecedor e de análises públicas, com as fontes acima. Confira sempre a versão corrigida no advisory oficial antes de agir.
It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directories are not protected by the usual default configuration "require all denied", these requests can succeed. If CGI scripts are also enabled for these aliased pathes, this could allow for remote code execution. This issue only affects Apache 2.4.49 and Apache 2.4.50 and not earlier versions.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Produtos afetados
Apache Software Foundation · Apache HTTP ServerPoCs públicas encontradas — 73✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/50512exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/50406exploitdbwww.exploit-db.com/exploits/50446não verificadogithubgithub.com/walnutsecurity/cve-2021-42013★ 27githubgithub.com/Vulnmachines/cve-2021-42013★ 15githubgithub.com/asaotomo/CVE-2021-42013-Apache-RCE-Poc-Exp★ 10githubgithub.com/andrea-mattioli/apache-exploit-CVE-2021-42013★ 9githubgithub.com/K3ysTr0K3R/CVE-2021-42013-EXPLOIT★ 7githubgithub.com/TheLastVvV/CVE-2021-42013_Reverse-Shell★ 7githubgithub.com/BassoNicolas/CVE-2021-42013★ 3githubgithub.com/twseptian/cve-2021-42013-docker-lab★ 2githubgithub.com/TheLastVvV/CVE-2021-42013★ 2githubgithub.com/bananoname/cve-2021-42013★ 1githubgithub.com/Hamesawian/CVE-2021-42013★ 1githubgithub.com/jas9reet/CVE-2021-42013-LAB★ 1githubgithub.com/cybfar/cve-2021-42013-httpd★ 1githubgithub.com/robotsense1337/CVE-2021-42013★ 1githubgithub.com/drackyjr/CVE-2021-42013★ 1githubgithub.com/vudala/CVE-2021-42013★ 1githubgithub.com/asepsaepdin/CVE-2021-42013★ 0githubgithub.com/Makavellik/POC-CVE-2021-42013-EXPLOIT★ 0githubgithub.com/FakhriCRD/Apache-CVE-2021-42013-RCE-Exploit★ 0githubgithub.com/ranasen-rat/cve-2021-42013★ 0githubgithub.com/zeynepglygt/apache-cve-2021-42013-rce★ 0githubgithub.com/Joapath/CVE-2021-42013★ 0githubgithub.com/eunho87/CVE-2021-42013★ 0githubgithub.com/berraesen/apache-cve-2021-42013-lab★ 0githubgithub.com/LayarKacaSiber/CVE-2021-42013★ 0githubgithub.com/viliuspovilaika/cve-2021-42013★ 0githubgithub.com/hadrian3689/apache_2.4.50★ 0githubgithub.com/mightysai1997/cve-2021-42013★ 0githubgithub.com/mightysai1997/cve-2021-42013L★ 0githubgithub.com/mightysai1997/cve-2021-42013.get★ 0githubgithub.com/12345qwert123456/CVE-2021-42013★ 0githubgithub.com/xMohamed0/CVE-2021-42013-ApacheRCE★ 0githubgithub.com/dream434/cve-2021-42013-apache★ 0vulncheckvulncheck.com/xdb/94a8be0205aenão verificadovulncheckvulncheck.com/xdb/1cfa52b1622bnão verificadovulncheckvulncheck.com/xdb/4c0e3155c6denão verificadovulncheckvulncheck.com/xdb/9db94a24977cnão verificadocve_referencepacketstormsecurity.com/files/164501/Apache-HTTP-Server-2.4.50-Path-Traversal-Code-Execution.htmlnão verificadocve_referencepacketstormsecurity.com/files/164609/Apache-HTTP-Server-2.4.50-Remote-Code-Execution.htmlnão verificadocve_referencepacketstormsecurity.com/files/164629/Apache-2.4.49-2.4.50-Traversal-Remote-Code-Execution.htmlnão verificadocve_referencepacketstormsecurity.com/files/164941/Apache-HTTP-Server-2.4.50-Remote-Code-Execution.htmlnão verificadocve_referencepacketstormsecurity.com/files/165089/Apache-HTTP-Server-2.4.50-CVE-2021-42013-Exploitation.htmlnão verificadocve_referencepacketstormsecurity.com/files/167397/Apache-2.4.50-Remote-Code-Execution.htmlnão verificadovulncheckvulncheck.com/xdb/05376c442191não verificadovulncheckvulncheck.com/xdb/80019b8370afnão verificadovulncheckvulncheck.com/xdb/cc14508a170cnão verificadovulncheckvulncheck.com/xdb/1164c6167307não verificadovulncheckvulncheck.com/xdb/4bad25e994e2não verificadovulncheckvulncheck.com/xdb/5ca2b55d2782não verificadovulncheckvulncheck.com/xdb/f480a19ee326não verificadovulncheckvulncheck.com/xdb/7f1b705bcf83não verificadovulncheckvulncheck.com/xdb/28d7e8231b1fnão verificadovulncheckvulncheck.com/xdb/7ff49021c22enão verificadovulncheckvulncheck.com/xdb/f7ab4f8db55bnão verificadovulncheckvulncheck.com/xdb/b07b7850bf05não verificadovulncheckvulncheck.com/xdb/ef11e24302d0não verificadovulncheckvulncheck.com/xdb/bfc30889d329não verificadovulncheckvulncheck.com/xdb/5e64583b49f2não verificadovulncheckvulncheck.com/xdb/b1d2ff60b684não verificadovulncheckvulncheck.com/xdb/6fea2c044e7anão verificadovulncheckvulncheck.com/xdb/1049bafbb722não verificadovulncheckvulncheck.com/xdb/93027facc9f9não verificadovulncheckvulncheck.com/xdb/56bd1b4d31bbnão verificadovulncheckvulncheck.com/xdb/e543e9003746não verificadovulncheckvulncheck.com/xdb/c9583159535cnão verificadovulncheckvulncheck.com/xdb/e7a565f8ed42não verificadovulncheckvulncheck.com/xdb/e3d6c5260840não verificadovulncheckvulncheck.com/xdb/699d0a790bc9não verificadovulncheckvulncheck.com/xdb/dd76d0d27f2anão verificadovulncheckvulncheck.com/xdb/b892ed4cf747não verificado⚠ Recursos públicos, para você avaliar a exposição de sistemas que controla ou está autorizado a testar. Teste apenas com autorização.
Referências
http://jvn.jp/en/jp/JVN51106450/index.htmlhttp://packetstormsecurity.com/files/164501/Apache-HTTP-Server-2.4.50-Path-Traversal-Code-Execution.htmlhttp://packetstormsecurity.com/files/164609/Apache-HTTP-Server-2.4.50-Remote-Code-Execution.htmlhttp://packetstormsecurity.com/files/164629/Apache-2.4.49-2.4.50-Traversal-Remote-Code-Execution.htmlhttp://packetstormsecurity.com/files/164941/Apache-HTTP-Server-2.4.50-Remote-Code-Execution.htmlhttp://packetstormsecurity.com/files/165089/Apache-HTTP-Server-2.4.50-CVE-2021-42013-Exploitation.htmlhttp://packetstormsecurity.com/files/167397/Apache-2.4.50-Remote-Code-Execution.htmlhttps://httpd.apache.org/security/vulnerabilities_24.htmlhttps://lists.apache.org/thread.html/r17a4c6ce9aff662efd9459e9d1850ab4a611cb23392fc68264c72cb3%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r7c795cd45a3384d4d27e57618a215b0ed19cb6ca8eb070061ad5d837%40%3Cannounce.apache.org%3Ehttps://lists.apache.org/thread.html/rb5b0e46f179f60b0c70204656bc52fcb558e961cb4d06a971e9e3efb%40%3Cusers.httpd.apache.org%3Ehttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RMIIEFINL6FUIOPD2A3M5XC6DH45Y3CC/