
Docker-basierte Reproduktion von CVE-2021-41773, der Path-Traversal- und RCE-Schwachstelle im Apache HTTP Server 2.4.49, mit httpd.conf-Einrichtung zum Testen.
Apache HTTP Server-Schwachstelle (funktioniert nur mit 2.4.49)
httpd.conf
...
<IfModule mpm_prefork_module>
LoadModule cgi_module modules/mod_cgi.so # diese Zeile auskommentieren
</IfModule>
...
<Directory />
AllowOverride none
# Require all denied # diese Zeile auskommentieren oder auf `Require all granted` setzen
</Directory>
...