Website Security & Threat Management
Helping Apache Servers stay safe from zero-day path traversal attacks (CVE-2021-41773)

Helping Apache Servers stay safe from zero-day path traversal attacks (CVE-2021-41773)

10/8/2021 · Michael Tremante

What this post added

This post details how Cloudflare's Web Application Firewall (WAF) and URL normalization features provided protection against CVE-2021-41773, a zero-day path traversal vulnerability in Apache HTTP Server. It explains the vulnerability's mechanism, which involves missing path normalization logic, and provides specific WAF rule IDs and descriptions that mitigate the exploit. The post also includes observed exploit attempts and emphasizes the importance of layered security measures.

Read the original post ↗