Apache · HTTP Server
CVE-2021-41773
Apache HTTP Server Path Traversal Vulnerability
CISA KEV record
- CISA date added
- 2021-11-03
- CISA due date
- 2021-11-17
- Known ransomware use
- Known
NVD risk context
9.8 CRITICAL
CVSS is a technical severity score. CISA’s KEV status remains the evidence that this vulnerability is known to be exploited.
Description
Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by Alias-like directives are not under default �require all denied� or if CGI scripts are enabled. The original patch issued under this CVE ID is insufficient, please review remediation information under CVE-2021-42013.
Required action
Apply updates per vendor instructions.
NVD reference index
Vendor and remediation references
NVD has tagged these sources as vendor advisories, patches, mitigations, or release notes.
- http://www.openwall.com/lists/oss-security/2021/10/11/4 ↗
- http://www.openwall.com/lists/oss-security/2021/10/15/3 ↗
- https://httpd.apache.org/security/vulnerabilities_24.html ↗
- https://lists.apache.org/thread.html/r17a4c6ce9aff662efd9459e9d1850ab4a611cb23392fc68264c72cb3%40%3Ccvs.httpd.apache.org%3E ↗
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RMIIEFINL6FUIOPD2A3M5XC6DH45Y3CC/ ↗
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WS5RVHOIIRECG65ZBTZY7IEJVWQSQPG3/ ↗
- https://www.oracle.com/security-alerts/cpujan2022.html ↗
Other NVD references (23)
- http://packetstormsecurity.com/files/164418/Apache-HTTP-Server-2.4.49-Path-Traversal-Remote-Code-Execution.html ↗
- http://packetstormsecurity.com/files/164418/Apache-HTTP-Server-2.4.49-Path-Traversal.html ↗
- http://packetstormsecurity.com/files/164629/Apache-2.4.49-2.4.50-Traversal-Remote-Code-Execution.html ↗
- http://packetstormsecurity.com/files/164941/Apache-HTTP-Server-2.4.50-Remote-Code-Execution.html ↗
- http://www.openwall.com/lists/oss-security/2021/10/05/2 ↗
- http://www.openwall.com/lists/oss-security/2021/10/07/1 ↗
- http://www.openwall.com/lists/oss-security/2021/10/07/6 ↗
- http://www.openwall.com/lists/oss-security/2021/10/08/1 ↗
- http://www.openwall.com/lists/oss-security/2021/10/08/2 ↗
- http://www.openwall.com/lists/oss-security/2021/10/08/3 ↗
- http://www.openwall.com/lists/oss-security/2021/10/08/4 ↗
- http://www.openwall.com/lists/oss-security/2021/10/08/5 ↗
- http://www.openwall.com/lists/oss-security/2021/10/08/6 ↗
- http://www.openwall.com/lists/oss-security/2021/10/09/1 ↗
- http://www.openwall.com/lists/oss-security/2021/10/16/1 ↗
- https://lists.apache.org/thread.html/r6abf5f2ba6f1aa8b1030f95367aaf17660c4e4c78cb2338aee18982f%40%3Cusers.httpd.apache.org%3E ↗
- https://lists.apache.org/thread.html/r7c795cd45a3384d4d27e57618a215b0ed19cb6ca8eb070061ad5d837%40%3Cannounce.apache.org%3E ↗
- https://lists.apache.org/thread.html/r98d704ed4377ed889d40479db79ed1ee2f43b2ebdd79ce84b042df45%40%3Cannounce.apache.org%3E ↗
- https://lists.apache.org/thread.html/rb5b0e46f179f60b0c70204656bc52fcb558e961cb4d06a971e9e3efb%40%3Cusers.httpd.apache.org%3E ↗
- https://security.gentoo.org/glsa/202208-20 ↗
- https://security.netapp.com/advisory/ntap-20211029-0009/ ↗
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-httpd-pathtrv-LAzg68cZ ↗
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-41773 ↗
MITRE CWE context
CWE classification
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
View official MITRE CWE details ↗NVD record timing
NVD record timeline
These dates describe NVD’s record, not CISA’s KEV addition or remediation due date.
- NVD published
- Oct 05, 2021, 09:15 AM UTC When NVD first published this CVE record.
- NVD last updated
- Jun 17, 2026, 04:08 AM UTC When NVD last changed its analysis or record data.
Advanced: view the technical CVSS vector
This standardized code is intended for security tools and technical analysts. The plain-language risk summary above explains its main points.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA notes
https://nvd.nist.gov/vuln/detail/CVE-2021-41773