VDB
BIT-apache-2021-42013
BIT-apache-2021-42013
PUBLISHED
CVSS 9.800000190734863 CRITICAL
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
Risk Scores
CVSS 3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | apache | 2.4.49, 2.4.50, 2.4.49 |
Timeline
- Mar 6, 2024 CVE Published
- Oct 22, 2025 CVE Updated
References
- http://packetstormsecurity.com/files/164609/Apache-HTTP-Server-2.4.50-Remote-Code-Execution.html url
- http://www.openwall.com/lists/oss-security/2021/10/07/6 url
- http://www.openwall.com/lists/oss-security/2021/10/08/5 url
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-httpd-pathtrv-LAzg68cZ url
- http://www.openwall.com/lists/oss-security/2021/10/08/1 url
- http://www.openwall.com/lists/oss-security/2021/10/08/6 url
- http://packetstormsecurity.com/files/164941/Apache-HTTP-Server-2.4.50-Remote-Code-Execution.html url
- http://www.openwall.com/lists/oss-security/2021/10/11/4 url
- http://www.openwall.com/lists/oss-security/2021/10/16/1 url
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-42013 url
- http://www.openwall.com/lists/oss-security/2021/10/15/3 url
- https://lists.apache.org/thread.html/rb5b0e46f179f60b0c70204656bc52fcb558e961cb4d06a971e9e3efb%40%3Cusers.httpd.apache.org%3E url
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WS5RVHOIIRECG65ZBTZY7IEJVWQSQPG3/ url
- http://packetstormsecurity.com/files/164629/Apache-2.4.49-2.4.50-Traversal-Remote-Code-Execution.html url
- https://www.povilaika.com/apache-2-4-50-exploit/ url
- http://jvn.jp/en/jp/JVN51106450/index.html url
- http://www.openwall.com/lists/oss-security/2021/10/09/1 url
- https://lists.apache.org/thread.html/r7c795cd45a3384d4d27e57618a215b0ed19cb6ca8eb070061ad5d837%40%3Cannounce.apache.org%3E url
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RMIIEFINL6FUIOPD2A3M5XC6DH45Y3CC/ url
- https://www.oracle.com/security-alerts/cpujan2022.html url
…and 12 more