Vulnerability threat dossier

CVE-2021-41773

apachehttp server

A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directories are not protected by the usual default configuration "require all denied", these requests can succeed. If CGI scripts are also enabled for these aliased pathes, this could allow for remote code execution. This issue is known to be exploited in the wild. This issue only affects Apache 2.4.49 and not earlier versions. The fix in Apache HTTP Server 2.4.50 was found to be incomplete, see CVE-2021-42013.

VTP deterministic threat50.0of 100 · CVSS excluded

VTP analyst assessment

Apache HTTP Server 2.4.49 path traversal

AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateREVIEWED
AI priorityNONE
AI confidence95%
Public exploitation · VTP factKEV

Assessment

Apache HTTP Server 2.4.49 contains a network-reachable path-normalization flaw that can expose files outside configured directories and may enable further impact when CGI is enabled. It has CVSS 9.8, is KEV-listed, and KEV associates it with known ransomware use.

Why it matters

  • Unauthenticated, low-complexity requests can have high confidentiality, integrity, and availability impact under affected configurations.
  • KEV establishes exploitation globally; EPSS 0.99992 indicates exceptionally high predicted exploitation likelihood but is not observation evidence.

Evidence

1 record references and 2 source references passed trusted post-response validation. The current deterministic record contains 0 independent evidence groups.

Uncertainties

Whether Apache 2.4.49, permissive file access, or CGI is present is unknown.

No first-party telemetry, supporting assertions, source text, or known exploit artifact is supplied.

First-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.

Next watchpoint

Inventory for Apache HTTP Server 2.4.49 and verify remediation.

AI baseline history (1)
  1. BASELINE ASSESSED
    Apache HTTP Server 2.4.49 path traversalgpt-5.6-sol · high
Technical severityCRITICALCVSS 9.8 · technical context
Public exploitationKEVGlobal public evidence
Exploit maturityNONE KNOWNReliability not implied
EPSS1.00100th percentile · prediction
Evidence confidence0%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.
Availability: SENSOR_ONLINE_NO_MATCHING_ACTIVITY · Evidence: UNKNOWN
HIGH

Honeypot request semantics are strongly consistent with CVE-2021-41773. This identifies likely attack intent, not successful exploitation or execution.

STRONGLY COMPATIBLETechnical consistency 95/100

Basis: deterministic technical candidate

Strongly consistent attempt; successful exploitation not observedDisclosure embargo completed
01

VTP deterministic assessment

Why this matters

  1. 01

    CISA KEV lists this vulnerability as known to be exploited globally.

  2. 02

    EPSS is 1.00; this is predictive context, not exploitation evidence.

  3. 03

    First-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.

02

Material change ledger

What changed

KEV ADDEDCISA KEV entry added
03

Claim provenance

Evidence and source independence

0publications detected
0underlying evidence chains

0 primary sources · 0 dependent secondary reports · 0 reports with unresolved independence. Repetition remains visible without multiplying confirmation.

04

Event history

Threat timeline

  1. 00:0003 Nov
    KEV ADDED

    CISA KEV entry added

    CISA lists global known exploitation. This is not a VTP sensor observation.

05

Original publications

Source record

06

Technical vulnerability data

Context, not threat proof

VTP threat score50.0vtp-threat-v1-public
Public exploitation30 / 30
EPSS prediction20 / 20
Exploit availability0 / 15
Source independence0 / 15
Intelligence recency0 / 10
Threat acceleration0 / 10
CVSS technical severityExcluded
CVSS
9.8 · CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-22
CPE records
7
Deterministic history records
20
Primary technical reference
07

Raw observations

First-party sensor records

First-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.