漏洞描述
A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to files outside the expected document root. If files outside of the document root are not protected by "require all denied" these requests can succeed. Additionally, this flaw could leak the source of interpreted files like CGI scripts. This issue is known to be exploited in the wild. This issue only affects Apache 2.4.49 and not earlier versions.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
github.comhttps://github.com/apache/httpd/commit/e150697086e70c552b2588f369f2d17815cb1782↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2021-41773↗cve.mitre.orghttps://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-41773↗twitter.comhttps://twitter.com/ptswarm/status/1445376079548624899↗twitter.comhttps://twitter.com/h4x0r_dz/status/1445401960371429381↗github.comhttps://github.com/blasty/CVE-2021-41773↗