Apache HTTP Server could allow a remote attacker to execute arbitrary code on the system caused by a path traversal vulnerability related to an incomplete fix for CVE-2021-41773 when mod_cgi is enabled. By uploading a file and setting permissions, an attacker could exploit this vulnerability to execute arbitrary code on the system with Apache user privileges.
Apache HTTP Server 2.4.49
Apache HTTP Server 2.4.50
Upgrade to the latest version of Apache HTTP Server, available from the Apache Website.