boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2021-42013

Apache Software Foundation Apache HTTP Server — Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS    %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .9996   100.0   YES
AFFECTED
  Product             Versions                     Fixed
  Apache HTTP Server  Apache HTTP Server 2.4.49 –  —
TIMELINE
  Oct 6   Reserved by apache
  Oct 7   Published (CNA: apache)
  Nov 3   Added to CISA KEV, remediation due 2021-11-17
CWE-22 · CNA: apache · CVSS v3.1 · 31 references · KEV due November 17, 2021

Description

It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directories are not protected by the usual default configuration "require all denied", these requests can succeed. If CGI scripts are also enabled for these aliased pathes, this could allow for remote code execution. This issue only affects Apache 2.4.49 and Apache 2.4.50 and not earlier versions.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
October 6, 2021ReservedReserved by apache
October 7, 2021PublishedPublished (CNA: apache)
November 3, 2021KEV ADDEDAdded to CISA KEV, remediation due 2021-11-17

Affected

Affected products and packages — 1 row
VendorProduct / PackageEcosystemVersion introducedFixed
Apache Software FoundationApache HTTP Server—Apache HTTP Server 2.4.49—

Weaknesses

CWE-22

References (31)

Related

Authoritative record: CVE-2021-42013 at cve.org

Vendors: apache

Weaknesses: CWE-22

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2021-42013 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Thursday, October 8, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.