VORANT. Threat Intelligence Sign in Get the full feed

Apache HTTP Server path traversal exploited in Japan

high vulnerability

Attackers are actively exploiting a path traversal/RCE flaw in Apache HTTP Server (CVE-2021-41773, CVE-2021-42013), with attacks observed in Japan; users must update to 2.4.51.

IPA (Japan's Information-technology Promotion Agency) issued an alert regarding a path traversal vulnerability in Apache HTTP Server that allows remote attackers to access files outside the document root. The vulnerability, tracked as CVE-2021-41773, has been confirmed as actively exploited in the wild, including attacks observed within Japan, prompting urgent calls for patching.

Apache's initial fix in version 2.4.50 was found to be incomplete, leading to a second CVE (CVE-2021-42013) covering the same underlying issue, which in some configurations can escalate to remote code execution. Apache released version 2.4.51 to fully address both vulnerabilities. IPA updated its advisory twice, first to note active exploitation observed domestically, and again to reflect the insufficient patch and new version release, urging all users to update immediately.

This vulnerability affects any organization running unpatched Apache HTTP Server 2.4.49 or 2.4.50, given the software's widespread use across web infrastructure. The combination of public exploitation and an initially incomplete patch increased urgency and risk during the disclosure window.

Mentioned in this report

Vulnerabilities CVE-2021-41773KEVCVE-2021-42013KEV

Source reporting: https://www.ipa.go.jp/archive/security/security-alert/2021/alert20211006.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free