Apache HTTP Server, Remote Code Execution, CVE-2021-42013 (Critical)

Listen to this Post

How the mentioned CVE works:

CVE-2021-42013 is a path traversal and remote code execution vulnerability in Apache HTTP Server versions 2.4.49 and 2.4.50. The flaw is an insufficient fix for CVE-2021-41773. It occurs due to a deficiency in the path normalization algorithm. An attacker can craft a malicious request using encoded URL characters, such as `%2e%2e` for traversing directories. If the `require all denied` directive is absent, this allows the attacker to bypass security constraints and map URLs to files outside the expected document root directories. Crucially, if mod_cgi is enabled and a CGI script is present in an accessible directory, the attacker can send a specially crafted request that leads to the execution of arbitrary shell commands on the server with the privileges of the web server process, achieving remote code execution.
Platform: Apache HTTP Server
Version: 2.4.49/2.4.50

Vulnerability : Path Traversal RCE

Severity: Critical

date: 2021-10-07

Prediction: 2021-10-07

What Undercode Say:

`curl -H “Content-Length: 0” -X POST http://vulnerable.host/cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh -d “echo; id”`

`cat /etc/passwd`

`nmap –script http-vuln-cve2021-42013 -p 80 target_ip`

How Exploit:

Craft malicious HTTP request.

Bypass path normalization.

Execute system commands.

Protection from this CVE

Update to 2.4.51.

Disable mod_cgi.

Use `Require all denied`.

Impact:

Remote Code Execution.

Information Disclosure.

System Compromise.

🎯Let’s Practice Exploiting & Learn Patching For Free:

Sources:

Reported By: nvd.nist.gov
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top