logo

Protecting cloud environments from the new critical Apache HTTP Server vulnerability

ID: 2f64de97-f2f4-5b89-b2b7-2bea6d7bf40b

STIX ID: report--2f64de97-f2f4-5b89-b2b7-2bea6d7bf40b

Feed Name: Wiz Blog

Threat Score
85/100

Date Published: 2021-10-08

Date Updated: 2026-05-01

...
...

This report details CVE-2021-41773/CVE-2021-42013 — a path traversal and file-disclosure vulnerability introduced in Apache HTTP Server 2.4.49 (with incomplete fixes in 2.4.50 and fully fixed in 2.4.51) — noting active in-the-wild exploitation and published RCE exploits, the particular danger to cloud environments where exposed servers can reveal high-permission cloud keys enabling environment takeover, and recommended immediate patching, access restriction, and secrets-hardening steps.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.