Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-38285

Опубликовано: 26 июл. 2023
Источник: redhat
CVSS3: 7.5

Описание

Trustwave ModSecurity 3.x before 3.0.10 has Inefficient Algorithmic Complexity.

A vulnerability was found in Trustwave's ModSecurity project due to an inefficient algorithmic complexity flaw. This issue is present in four transformation actions: removeWhitespace, removeNull, replaceNull, and removeCommentsChar. By sending a maliciously crafted HTTP request, an attacker could trigger worst-case performance, causing a denial of service.

Отчет

ModSecurity v2.x is not affected. CVE-2023-38285 only affects ModSecurity v3.x releases. None of our products ship ModSecurity v3.x builds. Therefore, Red Hat Enterprise Linux, Red Hat Software Collections, and Red Hat JBoss Core Services are not affected by this CVE.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7mod_securityNot affected
Red Hat Enterprise Linux 8mod_securityNot affected
Red Hat Enterprise Linux 9mod_securityNot affected
Red Hat JBoss Core Servicesjbcs-httpd24-mod_securityNot affected
Red Hat JBoss Core Servicesmod_securityNot affected
Red Hat Software Collectionshttpd24-mod_securityNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=2226930mod_security: DoS Vulnerability in Four Transformations

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 2 лет назад

Trustwave ModSecurity 3.x before 3.0.10 has Inefficient Algorithmic Complexity.

CVSS3: 7.5
nvd
больше 2 лет назад

Trustwave ModSecurity 3.x before 3.0.10 has Inefficient Algorithmic Complexity.

CVSS3: 7.5
debian
больше 2 лет назад

Trustwave ModSecurity 3.x before 3.0.10 has Inefficient Algorithmic Co ...

CVSS3: 7.5
github
больше 2 лет назад

Trustwave ModSecurity 3.x before 3.0.10 has Inefficient Algorithmic Complexity.

suse-cvrf
больше 2 лет назад

Security update for modsecurity

7.5 High

CVSS3