Direct naar de inhoud
Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
cybernieuws.nl Cybersecurity en informatiebeveiling nieuws alerts live · net nu 102 bronnen 1 kritiek 35 vandaag
CVE's Videos

← Terug naar CVE-database

CVE-2021-42013

CRITICAL · 9.5 CVSS Gepubliceerd: CWE-22

Beschrijving

Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by Alias-like directives are not under default require all denied or if CGI scripts are enabled. This CVE ID resolves an incomplete patch for CVE-2021-41773.

Required action: Apply updates per vendor instructions.

Vendors

Apache

Affected products

Http Server

References