CVE-2021-41773This vulnerability is part of CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation in the wild. It has been observed in ransomware campaigns.
Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by Alias-like directives are not under default �require all denied� or if CGI scripts are enabled. The original patch issued under this CVE ID is insufficient, please review remediation information under CVE-2021-42013.
Apache
HTTP Server
See vendor advisoryThis vulnerability was identified in HTTP Server by Apache. Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by Alias-like directives are not under default �require all denied� or if CGI scripts are enabled. The original patch issued under this CVE ID is insufficient, please review remediation information under CVE-2021-42013.
High - Known ransomware exploitation
Complete system compromise possible
https://nvd.nist.gov/vuln/detail/CVE-2021-41773
Apply updates per vendor instructions.
Due Date: 11/17/2021