It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directories are not protected by the usual default configuration "require all denied", these requests can succeed. If CGI scripts are also enabled for these aliased pathes, this could allow for remote code execution. This issue only affects Apache 2.4.49 and Apache 2.4.50 and not earlier versions.
AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateREVIEWED
AI priorityNONE
AI confidence98%
Public exploitation · VTP factKEV
Assessment
An incomplete fix permits remote path traversal in Apache HTTP Server 2.4.49 and 2.4.50; requests can access files outside configured aliases, and CGI-enabled configurations may extend the impact. CISA KEV confirms global exploitation and known ransomware-campaign use; CVSS is 9.8 and EPSS is 0.99964.
Why it matters
Unauthenticated network requests can access unintended files and may produce more severe outcomes where CGI is enabled.
KEV explicitly records known ransomware-campaign use.
Evidence
1 record references and 2 source references passed trusted post-response validation. The current deterministic record contains 0 independent evidence groups.
Uncertainties
The supplied description is truncated, and actual impact depends on file protections and CGI configuration.
Exploit availability is reported as none known; server exposure and first-party observation are unknown.
First-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.
Next watchpoint
Apache HTTP Server 2.4.49 or 2.4.50, especially with CGI enabled.
AI baseline history (1)
BASELINE ASSESSED
Apache HTTP Server path traversalgpt-5.6-sol · high
Evidence confidence0%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.
Honeypot request semantics are strongly consistent with CVE-2021-42013. This identifies likely attack intent, not successful exploitation or execution.
CISA KEV lists this vulnerability as known to be exploited globally.
02
EPSS is 1.00; this is predictive context, not exploitation evidence.
03
First-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.
02
Material change ledger
What changed
KEV ADDEDCISA KEV entry added
03
Claim provenance
Evidence and source independence
0publications detected
0underlying evidence chains
0 primary sources · 0 dependent secondary reports · 0 reports with unresolved independence. Repetition remains visible without multiplying confirmation.
04
Event history
Threat timeline
00:0003 Nov
KEV ADDED
CISA KEV entry added
CISA lists global known exploitation. This is not a VTP sensor observation.
First-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.