Skip to main content

Apache security briefs

52 published alerts for Apache products and services.

Actively exploited (KEV)Ransomware

CVE-2021-40438

Apache HTTP Server-Side Request Forgery (SSRF) vulnerability

Apache Apache is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-40438). A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier. CISA remediation due date: 2021-12-15. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2021-42013

Apache HTTP Server Path Traversal Vulnerability

Apache HTTP Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-42013). Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by Alias-like directives are not under default require all denied or if CGI scripts are enabled. This CVE ID resolves an incomplete patch for CVE-2021-41773. CISA remediation due date: 2021-11-17. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2021-41773

Apache HTTP Server Path Traversal Vulnerability

Apache HTTP Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-41773). Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by Alias-like directives are not under default �require all denied� or if CGI scripts are enabled. The original patch issued under this CVE ID is insufficient, please review remediation information under CVE-2021-42013. CISA remediation due date: 2021-11-17. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2017-5638

Apache Struts Remote Code Execution Vulnerability

Apache Struts is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2017-5638). Apache Struts Jakarta Multipart parser allows for malicious file upload using the Content-Type value, leading to remote code execution. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.