Protecting cloud environments from the new critical Apache HTTP Server vulnerability
ID: 2f64de97-f2f4-5b89-b2b7-2bea6d7bf40b
STIX ID: report--2f64de97-f2f4-5b89-b2b7-2bea6d7bf40b
Feed Name: Wiz Blog
Threat Score
This report details CVE-2021-41773/CVE-2021-42013 — a path traversal and file-disclosure vulnerability introduced in Apache HTTP Server 2.4.49 (with incomplete fixes in 2.4.50 and fully fixed in 2.4.51) — noting active in-the-wild exploitation and published RCE exploits, the particular danger to cloud environments where exposed servers can reveal high-permission cloud keys enabling environment takeover, and recommended immediate patching, access restriction, and secrets-hardening steps.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
