Apache · HTTP Server
CVE-2021-42013
Apache HTTP Server Path Traversal Vulnerability
CISA KEV record
- CISA date added
- 2021-11-03
- CISA due date
- 2021-11-17
- Known ransomware use
- Known
NVD risk context
9.8 CRITICAL
CVSS is a technical severity score. CISA’s KEV status remains the evidence that this vulnerability is known to be exploited.
Description
Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by Alias-like directives are not under default require all denied or if CGI scripts are enabled. This CVE ID resolves an incomplete patch for CVE-2021-41773.
Required action
Apply updates per vendor instructions.
NVD reference index
Vendor and remediation references
NVD has tagged these sources as vendor advisories, patches, mitigations, or release notes.
- https://httpd.apache.org/security/vulnerabilities_24.html ↗
- https://lists.apache.org/thread.html/r17a4c6ce9aff662efd9459e9d1850ab4a611cb23392fc68264c72cb3%40%3Ccvs.httpd.apache.org%3E ↗
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RMIIEFINL6FUIOPD2A3M5XC6DH45Y3CC/ ↗
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WS5RVHOIIRECG65ZBTZY7IEJVWQSQPG3/ ↗
- https://www.oracle.com/security-alerts/cpuapr2022.html ↗
- https://www.oracle.com/security-alerts/cpujan2022.html ↗
Other NVD references (25)
- http://jvn.jp/en/jp/JVN51106450/index.html ↗
- http://packetstormsecurity.com/files/164501/Apache-HTTP-Server-2.4.50-Path-Traversal-Code-Execution.html ↗
- http://packetstormsecurity.com/files/164609/Apache-HTTP-Server-2.4.50-Remote-Code-Execution.html ↗
- http://packetstormsecurity.com/files/164629/Apache-2.4.49-2.4.50-Traversal-Remote-Code-Execution.html ↗
- http://packetstormsecurity.com/files/164941/Apache-HTTP-Server-2.4.50-Remote-Code-Execution.html ↗
- http://packetstormsecurity.com/files/165089/Apache-HTTP-Server-2.4.50-CVE-2021-42013-Exploitation.html ↗
- http://packetstormsecurity.com/files/167397/Apache-2.4.50-Remote-Code-Execution.html ↗
- http://www.openwall.com/lists/oss-security/2021/10/07/6 ↗
- http://www.openwall.com/lists/oss-security/2021/10/08/1 ↗
- http://www.openwall.com/lists/oss-security/2021/10/08/2 ↗
- http://www.openwall.com/lists/oss-security/2021/10/08/3 ↗
- http://www.openwall.com/lists/oss-security/2021/10/08/4 ↗
- http://www.openwall.com/lists/oss-security/2021/10/08/5 ↗
- http://www.openwall.com/lists/oss-security/2021/10/08/6 ↗
- http://www.openwall.com/lists/oss-security/2021/10/09/1 ↗
- http://www.openwall.com/lists/oss-security/2021/10/11/4 ↗
- http://www.openwall.com/lists/oss-security/2021/10/15/3 ↗
- http://www.openwall.com/lists/oss-security/2021/10/16/1 ↗
- https://lists.apache.org/thread.html/r7c795cd45a3384d4d27e57618a215b0ed19cb6ca8eb070061ad5d837%40%3Cannounce.apache.org%3E ↗
- https://lists.apache.org/thread.html/rb5b0e46f179f60b0c70204656bc52fcb558e961cb4d06a971e9e3efb%40%3Cusers.httpd.apache.org%3E ↗
- https://security.gentoo.org/glsa/202208-20 ↗
- https://security.netapp.com/advisory/ntap-20211029-0009/ ↗
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-httpd-pathtrv-LAzg68cZ ↗
- https://www.povilaika.com/apache-2-4-50-exploit/ ↗
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-42013 ↗
MITRE CWE context
CWE classification
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
View official MITRE CWE details ↗NVD record timing
NVD record timeline
These dates describe NVD’s record, not CISA’s KEV addition or remediation due date.
- NVD published
- Oct 07, 2021, 04:15 PM UTC When NVD first published this CVE record.
- NVD last updated
- Jun 17, 2026, 04:09 AM UTC When NVD last changed its analysis or record data.
Advanced: view the technical CVSS vector
This standardized code is intended for security tools and technical analysts. The plain-language risk summary above explains its main points.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA notes
https://nvd.nist.gov/vuln/detail/CVE-2021-42013