CVE-2021-41773

CRITICAL KEV RANSOMWARE NUCLEI LAB

Apache 2.4.49/2.4.50 Traversal RCE

Title source: metasploit

Description

A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directories are not protected by the usual default configuration "require all denied", these requests can succeed. If CGI scripts are also enabled for these aliased pathes, this could allow for remote code execution. This issue is known to be exploited in the wild. This issue only affects Apache 2.4.49 and not earlier versions. The fix in Apache HTTP Server 2.4.50 was found to be incomplete, see CVE-2021-42013.

Exploits (169)

exploitdb WORKING POC VERIFIED
by Lucas Souza · bashwebappsmultiple
https://www.exploit-db.com/exploits/50383
nomisec WORKING POC 210 stars
by blasty · remote
https://github.com/blasty/CVE-2021-41773
nomisec SCANNER 148 stars
by inbug-team · poc
https://github.com/inbug-team/CVE-2021-41773_CVE-2021-42013
nomisec WORKING POC 63 stars
by HightechSec · poc
https://github.com/HightechSec/scarce-apache2
nomisec SCANNER 61 stars
by MrCl0wnLab · infoleak
https://github.com/MrCl0wnLab/SimplesApachePathTraversal
nomisec WORKING POC 49 stars
by iilegacyyii · remote
https://github.com/iilegacyyii/PoC-CVE-2021-41773
nomisec WORKING POC 39 stars
by Vulnmachines · remote
https://github.com/Vulnmachines/cve-2021-41773
nomisec WORKING POC 38 stars
by lorddemon · infoleak
https://github.com/lorddemon/CVE-2021-41773-PoC
nomisec WORKING POC 29 stars
by justakazh · infoleak
https://github.com/justakazh/mass_cve-2021-41773
nomisec WORKING POC 23 stars
by BlueTeamSteve · poc
https://github.com/BlueTeamSteve/CVE-2021-41773
nomisec SCANNER 22 stars
by im-hanzou · poc
https://github.com/im-hanzou/apachrot
nomisec WORKING POC 21 stars
by Ls4ss · remote
https://github.com/Ls4ss/CVE-2021-41773_CVE-2021-42013
nomisec SCANNER 17 stars
by ZephrFish · remote
https://github.com/ZephrFish/CVE-2021-41773-PoC
nomisec WORKING POC 15 stars
by wangfly-me · poc
https://github.com/wangfly-me/Apache_Penetration_Tool
nomisec WORKING POC 12 stars
by blackn0te · remote
https://github.com/blackn0te/Apache-HTTP-Server-2.4.49-2.4.50-Path-Traversal-Remote-Code-Execution
nomisec WORKING POC 12 stars
by itsecurityco · infoleak
https://github.com/itsecurityco/CVE-2021-41773
nomisec WORKING POC 12 stars
by Zeop-CyberSec · poc
https://github.com/Zeop-CyberSec/apache_normalize_path
nomisec WORKING POC 12 stars
by j4k0m · poc
https://github.com/j4k0m/CVE-2021-41773
nomisec WORKING POC 11 stars
by mr-exo · poc
https://github.com/mr-exo/CVE-2021-41773
nomisec WORKING POC 11 stars
by zeronine9 · poc
https://github.com/zeronine9/CVE-2021-41773
nomisec WORKING POC 9 stars
by aqiao-jashell · remote
https://github.com/aqiao-jashell/CVE-2021-41773
nomisec WORKING POC 9 stars
by theLSA · poc
https://github.com/theLSA/apache-httpd-path-traversal-checker
nomisec WORKING POC 9 stars
by 1nhann · poc
https://github.com/1nhann/CVE-2021-41773
nomisec WRITEUP 9 stars
by knqyf263 · poc
https://github.com/knqyf263/CVE-2021-41773
nomisec SCANNER 8 stars
by creadpag · infoleak
https://github.com/creadpag/CVE-2021-41773-POC
nomisec WORKING POC 8 stars
by CalfCrusher · remote
https://github.com/CalfCrusher/Path-traversal-RCE-Apache-2.4.49-2.4.50-Exploit
nomisec WORKING POC 8 stars
by numanturle · poc
https://github.com/numanturle/CVE-2021-41773
nomisec WORKING POC 7 stars
by aqiao-jashell · remote
https://github.com/aqiao-jashell/py-CVE-2021-41773
nomisec WORKING POC 7 stars
by 0xRar · poc
https://github.com/0xRar/CVE-2021-41773
nomisec WORKING POC 6 stars
by belajarqywok · remote
https://github.com/belajarqywok/CVE-2021-41773-MSF
nomisec WRITEUP 6 stars
by noflowpls · remote
https://github.com/noflowpls/CVE-2021-41773
nomisec WORKING POC 6 stars
by Hydragyrum · poc
https://github.com/Hydragyrum/CVE-2021-41773-Playground
nomisec WORKING POC 6 stars
by TishcaTpx · infoleak
https://github.com/TishcaTpx/POC-CVE-2021-41773
nomisec WORKING POC 4 stars
by OfriOuzan · remote
https://github.com/OfriOuzan/CVE-2021-41773_CVE-2021-42013_Exploits
nomisec WORKING POC 4 stars
by LudovicPatho · remote
https://github.com/LudovicPatho/CVE-2021-41773
nomisec WORKING POC 4 stars
by apapedulimu · poc
https://github.com/apapedulimu/Apachuk
nomisec WORKING POC 4 stars
by twseptian · poc
https://github.com/twseptian/cve-2021-41773
github WRITEUP 3 stars
by HxDDD · poc
https://github.com/HxDDD/CVE-PoC/tree/main/Apache/(Path Traversal) CVE-2021-41773.md
nomisec WORKING POC 3 stars
by superzerosec · remote
https://github.com/superzerosec/CVE-2021-41773
nomisec WORKING POC 3 stars
by jbovet · poc
https://github.com/jbovet/CVE-2021-41773
nomisec WORKING POC 3 stars
by habibiefaried · poc
https://github.com/habibiefaried/CVE-2021-41773-PoC
nomisec WORKING POC 2 stars
by RevShellXD · poc
https://github.com/RevShellXD/LFI-Destruction
nomisec WRITEUP 2 stars
by CyberQuestor-infosec · remote
https://github.com/CyberQuestor-infosec/CVE-2021-41773-Apache_2.4.49-Path-traversal-to-RCE
nomisec WORKING POC 2 stars
by walnutsecurity · remote
https://github.com/walnutsecurity/cve-2021-41773
nomisec WORKING POC 2 stars
by Habib0x0 · remote
https://github.com/Habib0x0/CVE-2021-41773
nomisec WORKING POC 2 stars
by iosifache · poc
https://github.com/iosifache/ApacheRCEEssay
nomisec WORKING POC 2 stars
by Chocapikk · remote
https://github.com/Chocapikk/CVE-2021-41773
nomisec WORKING POC 2 stars
by Soliux · poc
https://github.com/Soliux/CVE-2021-41773
nomisec WORKING POC 2 stars
by AssassinUKG · poc
https://github.com/AssassinUKG/CVE-2021-41773
nomisec WRITEUP 2 stars
by lopqto · poc
https://github.com/lopqto/CVE-2021-41773_Honeypot
nomisec SCANNER 2 stars
by jheeree · infoleak
https://github.com/jheeree/Simple-CVE-2021-41773-checker
nomisec WORKING POC 2 stars
by 5gstudent · poc
https://github.com/5gstudent/cve-2021-41773-and-cve-2021-42013
nomisec WORKING POC 2 stars
by orangmuda · poc
https://github.com/orangmuda/CVE-2021-41773
nomisec WORKING POC 1 stars
by mightysai1997 · infoleak
https://github.com/mightysai1997/CVE-2021-41773S
nomisec WORKING POC 1 stars
by adrianmafandy · remote
https://github.com/adrianmafandy/CVE-2021-41773
nomisec SCANNER 1 stars
by charanvoonna · remote
https://github.com/charanvoonna/CVE-2021-41773
nomisec WORKING POC 1 stars
by Zyx2440 · remote
https://github.com/Zyx2440/Apache-HTTP-Server-2.4.50-RCE
github WORKING POC 1 stars
by vadimgggg · pythonpoc
https://github.com/vadimgggg/CVE-PoC/tree/main/CVE-2021-41773
nomisec WORKING POC 1 stars
by Iris288 · remote
https://github.com/Iris288/CVE-2021-41773
nomisec WORKING POC 1 stars
by retrymp3 · remote
https://github.com/retrymp3/apache2.4.49VulnerableLabSetup
nomisec WORKING POC 1 stars
by TheKernelPanic · remote
https://github.com/TheKernelPanic/exploit-apache2-cve-2021-41773
nomisec WORKING POC 1 stars
by mightysai1997 · poc
https://github.com/mightysai1997/CVE-2021-41773m
nomisec WORKING POC 1 stars
by kubota · poc
https://github.com/kubota/POC-CVE-2021-41773
nomisec WORKING POC 1 stars
by shellreaper · poc
https://github.com/shellreaper/CVE-2021-41773
nomisec NO CODE 1 stars
by IcmpOff · poc
https://github.com/IcmpOff/Apache-2.4.49-2.4.50-Traversal-Remote-Code-Execution-Exploit
nomisec WORKING POC 1 stars
by corelight · poc
https://github.com/corelight/CVE-2021-41773
nomisec WORKING POC 1 stars
by MazX0p · poc
https://github.com/MazX0p/CVE-2021-41773
nomisec WRITEUP 1 stars
by zerodaywolf · poc
https://github.com/zerodaywolf/CVE-2021-41773_42013
nomisec WRITEUP 1 stars
by ksanchezcld · poc
https://github.com/ksanchezcld/httpd-2.4.49
nomisec SCANNER 1 stars
by EagleTube · poc
https://github.com/EagleTube/CVE-2021-41773
nomisec WORKING POC 1 stars
by n3k00n3 · poc
https://github.com/n3k00n3/CVE-2021-41773
nomisec WORKING POC 1 stars
by vinhjaxt · infoleak
https://github.com/vinhjaxt/CVE-2021-41773-exploit
nomisec WORKING POC 1 stars
by PentesterGuruji · poc
https://github.com/PentesterGuruji/CVE-2021-41773
nomisec WORKING POC 1 stars
by r00tVen0m · poc
https://github.com/r00tVen0m/CVE-2021-41773
nomisec WORKING POC 1 stars
by masahiro331 · poc
https://github.com/masahiro331/CVE-2021-41773
nomisec WORKING POC
by klmntbelgium · poc
https://github.com/klmntbelgium/cve-2021-41773-exploration
nomisec WRITEUP
by JKIM72403 · poc
https://github.com/JKIM72403/CS4277-CVE-Path-Traversal-Apache-HTTP-Server
nomisec WORKING POC
by Kouf320 · poc
https://github.com/Kouf320/attacker-lab-cve-2017-5638-cve-2021-41773-paper
gitlab WORKING POC
by entee28 · poc
https://gitlab.com/entee28/cve-2021-41773
nomisec WORKING POC
by snapdowgg · remote
https://github.com/snapdowgg/CVE-2021-41773
nomisec WORKING POC
by sobanahmed6061 · remote
https://github.com/sobanahmed6061/CVE-2021-41773-RedTeam
nomisec WORKING POC
by abds059 · remote
https://github.com/abds059/APACHE-PATH-TRAVERSAL-RCE-CVE-2021-41773-
nomisec WORKING POC
by Areeba-Zehra-Jafri · remote
https://github.com/Areeba-Zehra-Jafri/CVE-2021-41773---Apache-Path-Traversal---RCE
nomisec WORKING POC
by tsiddiquea · infoleak
https://github.com/tsiddiquea/cve-reproduction-lab
nomisec WORKING POC
by zubairahm3d · infoleak
https://github.com/zubairahm3d/apache-cve-2021-41773-lab
nomisec WORKING POC
by Nanxsec · poc
https://github.com/Nanxsec/exploitApache
gitlab WORKING POC
by sebast331-poc · poc
https://gitlab.com/sebast331-poc/cve-2021-41773
gitlab STUB
by ahmad4fifz · poc
https://gitlab.com/ahmad4fifz/docker-cve-2021-41773
gitlab WORKING POC
by vulnerability-writeup · poc
https://gitlab.com/vulnerability-writeup/cve-2021-41773
gitlab WORKING POC
by amstal93 · poc
https://gitlab.com/amstal93/cve-2021-41773
gitlab WORKING POC
by checkscale-gitlab · poc
https://gitlab.com/checkscale-gitlab/cve-2021-41773
gitlab WORKING POC
by bc-scale · remote
https://gitlab.com/bc-scale/cve-2021-41773
nomisec WORKING POC
by ISabbiI · remote
https://github.com/ISabbiI/PoC-Apache-CVE-2021-41773-Infrastructure-LAB
nomisec WORKING POC
by dserdyk3-arch · poc
https://github.com/dserdyk3-arch/Serdyuk-DO-homework-CVE-2021-41773
nomisec SCANNER
by sudo0xksh · poc
https://github.com/sudo0xksh/cve-2021-41773-checker
nomisec WRITEUP
by ChanaPCN · poc
https://github.com/ChanaPCN/CVE-2021-41773-Analysis
nomisec WORKING POC
by mightysai1997 · poc
https://github.com/mightysai1997/CVE-2021-41773h
nomisec WORKING POC
by mightysai1997 · infoleak
https://github.com/mightysai1997/CVE-2021-41773-PoC
nomisec WORKING POC
by mightysai1997 · remote
https://github.com/mightysai1997/CVE-2021-41773-i-
nomisec WORKING POC
by dileepdkumar · remote
https://github.com/dileepdkumar/LayarKacaSiber-CVE-2021-41773
nomisec SCANNER
by faizdotid · infoleak
https://github.com/faizdotid/CVE-2021-41773
nomisec NO CODE
by Mahfujurjust · poc
https://github.com/Mahfujurjust/CVE-2021-41773
nomisec WORKING POC
by gunzf0x · infoleak
https://github.com/gunzf0x/CVE-2021-41773
nomisec WRITEUP
by MuhammadHuzaifaAsif · poc
https://github.com/MuhammadHuzaifaAsif/security-lab
nomisec WRITEUP
by hackedrishi · remote
https://github.com/hackedrishi/CTF_WRITEUPS-TryHackMe-CVE-2021-41773-
nomisec WORKING POC
by mah4nzfr · remote
https://github.com/mah4nzfr/CVE-2021-41773
nomisec WORKING POC
by r0otk3r · remote
https://github.com/r0otk3r/CVE-2021-41773
nomisec WORKING POC
by blu3ming · infoleak
https://github.com/blu3ming/PoC-CVE-2021-41773
nomisec SCANNER
by psibot · poc
https://github.com/psibot/apache-vulnerable
nomisec WORKING POC
by AzkOsDev · poc
https://github.com/AzkOsDev/CVE-2021-41773
nomisec WORKING POC
by JIYUN02 · remote
https://github.com/JIYUN02/cve-2021-41773
nomisec WORKING POC
by khaidtraivch · remote
https://github.com/khaidtraivch/CVE-2021-41773-Apache-2.4.49-
nomisec WORKING POC
by luongchivi · remote
https://github.com/luongchivi/Preproduce-CVE-2021-41773
nomisec WRITEUP
by ashique-thaha · remote
https://github.com/ashique-thaha/CVE-2021-41773-POC
nomisec WORKING POC
by javaamo · remote
https://github.com/javaamo/CVE-2021-41773
nomisec WRITEUP
by Vanshuk-Bhagat · poc
https://github.com/Vanshuk-Bhagat/Apache-HTTP-Server-Vulnerabilities-CVE-2021-41773-and-CVE-2021-42013
nomisec WORKING POC
by tiemio · remote
https://github.com/tiemio/SSH-key-and-RCE-PoC-for-CVE-2021-41773
nomisec NO CODE
by Taldrid1 · infoleak
https://github.com/Taldrid1/cve-2021-41773
nomisec WORKING POC
by FakesiteSecurity · remote
https://github.com/FakesiteSecurity/CVE-2021-41773
nomisec WORKING POC
by redspy-sec · remote
https://github.com/redspy-sec/CVE-2021-41773
nomisec WORKING POC
by skentagon · remote
https://github.com/skentagon/CVE-2021-41773
nomisec WRITEUP
by jkska23 · poc
https://github.com/jkska23/Additive-Vulnerability-Analysis-CVE-2021-41773
nomisec WORKING POC
by 0xc4t · remote
https://github.com/0xc4t/CVE-2021-41773
nomisec SCANNER
by Maybe4a6f7365 · infoleak
https://github.com/Maybe4a6f7365/CVE-2021-41773
nomisec WORKING POC
by 0xGabe · remote
https://github.com/0xGabe/Apache-CVEs
nomisec WORKING POC
by MatanelGordon · infoleak
https://github.com/MatanelGordon/docker-cve-2021-41773
nomisec WORKING POC
by 12345qwert123456 · remote
https://github.com/12345qwert123456/CVE-2021-41773
nomisec WORKING POC
by mightysai1997 · infoleak
https://github.com/mightysai1997/CVE-2021-41773.git1
nomisec WORKING POC
by mightysai1997 · remote
https://github.com/mightysai1997/CVE-2021-41773-L-
nomisec WORKING POC
by mightysai1997 · remote
https://github.com/mightysai1997/cve-2021-41773-v-
nomisec WORKING POC
by mightysai1997 · remote
https://github.com/mightysai1997/cve-2021-41773
nomisec WRITEUP
by EkamSinghWalia · poc
https://github.com/EkamSinghWalia/Mitigation-Apache-CVE-2021-41773-
nomisec WORKING POC
by pwn3z · infoleak
https://github.com/pwn3z/CVE-2021-41773-Apache-RCE
nomisec WORKING POC
by ranggaggngntt · infoleak
https://github.com/ranggaggngntt/CVE-2021-41773
nomisec WORKING POC
by bernardas · poc
https://github.com/bernardas/netsec-polygon
nomisec SCANNER
by anldori · remote
https://github.com/anldori/CVE-2021-41773-Scanner
nomisec WORKING POC
by zer0qs · infoleak
https://github.com/zer0qs/CVE-2021-41773
nomisec WORKING POC
by vuongnv3389-sec · infoleak
https://github.com/vuongnv3389-sec/cve-2021-41773
nomisec WORKING POC
by DoTuan1 · infoleak
https://github.com/DoTuan1/Reserch-CVE-2021-41773
nomisec WORKING POC
by puckiestyle · remote
https://github.com/puckiestyle/CVE-2021-41773
nomisec WORKING POC
by i6c · poc
https://github.com/i6c/MASS_CVE-2021-41773
nomisec WORKING POC
by twseptian · poc
https://github.com/twseptian/cve-2021-41773-docker-lab
nomisec WORKING POC
by xMohamed0 · poc
https://github.com/xMohamed0/CVE-2021-41773
nomisec WORKING POC
by pirenga · poc
https://github.com/pirenga/CVE-2021-41773
nomisec STUB
by wolf1892 · poc
https://github.com/wolf1892/CVE-2021-41773
nomisec SCANNER
by vida003 · poc
https://github.com/vida003/Scanner-CVE-2021-41773
nomisec WORKING POC
by TheLastVvV · infoleak
https://github.com/TheLastVvV/CVE-2021-41773
nomisec WORKING POC
by LayarKacaSiber · remote
https://github.com/LayarKacaSiber/CVE-2021-41773
nomisec STUB
by BabyTeam1024 · poc
https://github.com/BabyTeam1024/CVE-2021-41773
nomisec WRITEUP
by shiomiyan · poc
https://github.com/shiomiyan/CVE-2021-41773
nomisec WORKING POC
by ch4os443 · poc
https://github.com/ch4os443/CVE-2021-41773
nomisec SCANNER
by b1tsec · poc
https://github.com/b1tsec/CVE-2021-41773
nomisec SCANNER
by pisut4152 · poc
https://github.com/pisut4152/Sigma-Rule-for-CVE-2021-41773-and-CVE-2021-42013-exploitation-attempt
nomisec SCANNER
by mohwahyudi · infoleak
https://github.com/mohwahyudi/cve-2021-41773
nomisec WORKING POC
by sixpacksecurity · poc
https://github.com/sixpacksecurity/CVE-2021-41773
nomisec WORKING POC
by Hattan515 · poc
https://github.com/Hattan515/POC-CVE-2021-41773
nomisec WORKING POC
by fnatalucci · poc
https://github.com/fnatalucci/CVE-2021-41773-RCE
nomisec SCANNER
by TAI-REx · poc
https://github.com/TAI-REx/cve-2021-41773-nse
vulncheck_xdb WORKING POC
remote
https://github.com/FakhriCRD/Apache-CVE-2021-42013-RCE-Exploit
vulncheck_xdb WORKING POC
remote
https://github.com/Ask-os/CVE-2021-41773
vulncheck_xdb WORKING POC
client-side
https://github.com/mmtalsi/toolbox
vulncheck_xdb WORKING POC
remote
https://github.com/dream434/cve-2021-42013-apache
vulncheck_xdb WORKING POC
remote
https://github.com/Fa1c0n35/CVE-2021-41773
vulncheck_xdb WORKING POC
remote
https://github.com/thehackersbrain/CVE-2021-41773
vulncheck_xdb WORKING POC
remote
https://github.com/mauricelambert/CVE-2021-41773
vulncheck_xdb WORKING POC
infoleak
https://github.com/norrig/CVE-2021-41773-exploiter
exploitdb WORKING POC
pythonwebappsmultiple
https://www.exploit-db.com/exploits/50512

Nuclei Templates (1)

Apache 2.4.49 - Path Traversal and Remote Code Execution
HIGHVERIFIEDby daffainfo,666asd
Shodan: Apache 2.4.49 || cpe:"cpe:2.3:a:apache:http_server" || apache 2.4.49

References (30)

... and 10 more

Scores

CVSS v3 9.8
EPSS 0.9439
EPSS Percentile 100.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Lab Environment

COMMUNITY
Community Lab
docker pull httpd:2.4.49-buster
docker pull httpd:2.4.49
docker pull vulhub/httpd:2.4.49
docker pull httpd:2.4.49-alpine
docker pull mcr.microsoft.com/windows/servercore:ltsc2019
+18 more images
+154 more repos

Details

CISA KEV 2021-11-03
VulnCheck KEV 2021-09-29
InTheWild.io 2021-09-29
ENISA EUVD EUVD-2021-28781
Ransomware Use Confirmed
CWE
CWE-22
Status published
Products (7)
apache/http_server 2.4.49
fedoraproject/fedora 34
fedoraproject/fedora 35
netapp/cloud_backup
oracle/instantis_enterprisetrack 17.1
oracle/instantis_enterprisetrack 17.2
oracle/instantis_enterprisetrack 17.3
Published Oct 05, 2021
KEV Added Nov 03, 2021
Tracked Since Feb 18, 2026