Oval Definition:oval:org.opensuse.security:def:202141773
Revision Date:2022-09-02Version:1
Title:CVE-2021-41773
Description:

A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directories are not protected by the usual default configuration "require all denied", these requests can succeed. If CGI scripts are also enabled for these aliased pathes, this could allow for remote code execution. This issue is known to be exploited in the wild. This issue only affects Apache 2.4.49 and not earlier versions. The fix in Apache HTTP Server 2.4.50 was found to be incomplete, see CVE-2021-42013.
Family:unixClass:vulnerability
Status:Reference(s):Mitre CVE-2021-41773
SUSE CVE-2021-41773
Platform(s):openSUSE Tumbleweed
SUSE CaaS Platform 4.0
SUSE Linux Enterprise Desktop 15 SP2
SUSE Linux Enterprise High Performance Computing 12 SP5
SUSE Linux Enterprise High Performance Computing 15 SP2
SUSE Linux Enterprise Module for Basesystem 15 SP2
SUSE Linux Enterprise Module for Server Applications 15 SP2
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server 15 SP2
SUSE Linux Enterprise Server for SAP Applications 12 SP4
SUSE Linux Enterprise Server for SAP Applications 12 SP5
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server for SAP Applications 15 SP1
SUSE Linux Enterprise Server for SAP Applications 15 SP2
SUSE Linux Enterprise Storage 7
SUSE Manager Proxy 4.1
SUSE Manager Retail Branch Server 4.1
SUSE Manager Server 4.1
SUSE OpenStack Cloud 8
SUSE OpenStack Cloud 9
SUSE OpenStack Cloud Crowbar 8
SUSE OpenStack Cloud Crowbar 9
Product(s):
Definition Synopsis
  • openSUSE Tumbleweed is installed
  • AND apache2-2.4.51-1.1 is installed
  • Definition Synopsis
  • Release Information
  • SUSE CaaS Platform 4.0 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 15 SP1 is installed
  • AND Package Information
  • apache2 is not affected
  • OR apache2-devel is not affected
  • OR apache2-doc is not affected
  • OR apache2-prefork is not affected
  • OR apache2-utils is not affected
  • OR apache2-worker is not affected
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Module for Server Applications 15 SP2 is installed
  • AND apache2 is not affected
  • OR Package Information
  • SUSE Linux Enterprise Module for Basesystem 15 SP2 is installed
  • AND
  • apache2 is not affected
  • OR apache2-prefork is not affected
  • OR apache2-utils is not affected
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Module for Server Applications 15 SP2 is installed
  • AND apache2 is not affected
  • OR Package Information
  • SUSE Linux Enterprise Module for Basesystem 15 SP2 is installed
  • AND
  • apache2 is not affected
  • OR apache2-prefork is not affected
  • OR apache2-utils is not affected
  • OR Package Information
  • SUSE Linux Enterprise Server for SAP Applications 15 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 15 SP1 is installed
  • AND
  • apache2 is not affected
  • OR apache2-devel is not affected
  • OR apache2-doc is not affected
  • OR apache2-prefork is not affected
  • OR apache2-utils is not affected
  • OR apache2-worker is not affected
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Desktop 15 SP2 is installed
  • OR SUSE Linux Enterprise High Performance Computing 15 SP2 is installed
  • OR SUSE Linux Enterprise Module for Basesystem 15 SP2 is installed
  • OR SUSE Linux Enterprise Server 15 SP2 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 15 SP2 is installed
  • OR SUSE Linux Enterprise Storage 7 is installed
  • OR SUSE Manager Proxy 4.1 is installed
  • OR SUSE Manager Retail Branch Server 4.1 is installed
  • OR SUSE Manager Server 4.1 is installed
  • AND apache2 is not affected
  • Definition Synopsis
  • SUSE Linux Enterprise Server for SAP Applications 15 SP1 is installed
  • AND Package Information
  • apache2 is not affected
  • OR apache2-devel is not affected
  • OR apache2-doc is not affected
  • OR apache2-prefork is not affected
  • OR apache2-utils is not affected
  • OR apache2-worker is not affected
  • Definition Synopsis
  • Release Information
  • SUSE OpenStack Cloud 8 is installed
  • OR SUSE OpenStack Cloud Crowbar 8 is installed
  • AND Package Information
  • apache2 is not affected
  • OR apache2-doc is not affected
  • OR apache2-example-pages is not affected
  • OR apache2-prefork is not affected
  • OR apache2-utils is not affected
  • OR apache2-worker is not affected
  • Definition Synopsis
  • Release Information
  • SUSE OpenStack Cloud 9 is installed
  • OR SUSE OpenStack Cloud Crowbar 9 is installed
  • AND Package Information
  • apache2 is not affected
  • OR apache2-doc is not affected
  • OR apache2-example-pages is not affected
  • OR apache2-prefork is not affected
  • OR apache2-utils is not affected
  • OR apache2-worker is not affected
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise High Performance Computing 12 SP5 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 12 SP5 is installed
  • AND apache2 is not affected
  • OR Package Information
  • SUSE Linux Enterprise Server 12 SP5 is installed
  • AND
  • apache2 is not affected
  • OR apache2-doc is not affected
  • OR apache2-example-pages is not affected
  • OR apache2-prefork is not affected
  • OR apache2-utils is not affected
  • OR apache2-worker is not affected
  • Definition Synopsis
  • SUSE Linux Enterprise Server for SAP Applications 12 SP4 is installed
  • AND Package Information
  • apache2 is not affected
  • OR apache2-doc is not affected
  • OR apache2-example-pages is not affected
  • OR apache2-prefork is not affected
  • OR apache2-utils is not affected
  • OR apache2-worker is not affected
  • BACK