Apache HTTP Server Could Allow for a Path Traversal Attack

Fortify Security Team
Oct 5, 2021

A vulnerability has been discovered in Apache HTTP Server, which could allow for a path traversal attack. Apache HTTP Server is an open-source, cross-platform web server for Unix and Windows. Successful exploitation allows threat actors to map URLs to files outside the expected document root by launching a path traversal attack and would give a remote attacker access to arbitrary files outside of the document root on the vulnerable web server. Additionally, exploits of this flaw may lead to the leaking of the source of interpreted files such as CGI scripts.

THREAT INTELLIGENCE: Apache has reported this vulnerability is actively being exploited in the wild.

SYSTEMS AFFECTED:

  • Apache HTTP Server 2.4.49

RISK:
Government:

  • Large and medium government entities: High
  • Small government entities: Medium

Businesses:

  • Large and medium business entities: High
  • Small business entities: Medium

Home users: Low

TECHNICAL SUMMARY:

A vulnerability has been discovered in Apache HTTP Server, which could allow for a path traversal attack. The vulnerability was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to files outside the expected document root. If files outside of the document root are not protected by the “require all denied” access control parameter, disabled be default, these requests can succeed. Additionally this flaw could leak the source of interpreted files like CGI scripts. Path traversal attacks involve sending requests to access backend or sensitive server directories that should be out of reach. With this vulnerability, the filters are bypassed by using encoded characters (ASCII) for the URLs. Successful exploitation allows threat actors to map URLs to files outside the expected document root by launching a path traversal attack and would give a remote attacker access to arbitrary files outside of the document root on the vulnerable web server. Additionally, exploits of this flaw may lead to the leaking of the source of interpreted files such as CGI scripts.

RECOMMENDATIONS:

We recommend the following actions be taken:

  • Apply the latest Apache HTTP Server patch (2.4.50) for your platform
  • Run all software as a non-privileged user (one without administrative privileges) to diminish the effects of a successful attack.
  • Remind users not to visit un-trusted websites or follow links provided by unknown or un-trusted sources.
  • Apply the Principle of Least Privilege to all systems and services.

REFERENCES:
CVE:
https://www.cve.org/CVERecord?id=CVE-2021-41773

Bleeping Computer:
https://www.bleepingcomputer.com/news/security/apache-fixes-actively-exploited-zero-day-vulnerability-patch-now/

Recent Posts

Adobe Products Vulnerabilities Allow for Arbitrary Code Execution

Multiple vulnerabilities have been discovered in Adobe products, the most severe of which could allow for arbitrary code execution. Animate is a multimedia authoring computer animation program. Bridge is a digital asset management application Illustrator is a vector...

Citrix ADM Allows Attacker to Reset the Administrator Password

Multiple vulnerabilities have been discovered in Citrix ADM. Citrix ADM is a web-based solution for managing all Citrix deployments. The most severe of these vulnerabilities Could Allow for an Unauthenticated Attacker to Reset the Administrator Password. THREAT...

June 2022 – Critical Patches Issued for Microsoft Products

Multiple vulnerabilities have been discovered in Microsoft products, the most severe of which could allow for remote code execution in the context of the logged on user. Depending on the privileges associated with the user, an attacker could then install programs;...