Apache 2.4.49 Security Bug - Upgrade to 2.4.50
If you are running Apache httpd 2.4.49, it has a bug similar to the original NCSA web server wherein it is possible to walk the entire file system, past the document root directory using ../../../.. constructs in a path. This is fixed in Apache httpd 2.4.50 (which we installed today).