Описание
ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Prior to 3.0.16, the multipart/form-data request body parser in libmodsecurity silently removes embedded line breaks from non-file form-field values before exporting them to ARGS and ARGS_POST because src/request_body_processor/multipart.cc overwrites reserved bytes in m_reserve instead of appending the current buffer. This creates a parser differential between ModSecurity and backend applications that preserve line breaks in form fields, allowing rules that inspect ARGS or ARGS_POST to miss payloads whose dangerous syntax depends on a line break. This issue is fixed in version 3.0.16.
A flaw was found in ModSecurity, an open-source web application firewall (WAF). The multipart/form-data request body parser in libmodsecurity incorrectly handles embedded line breaks in non-file form-field values. This discrepancy between ModSecurity and backend applications, which preserve line breaks, can allow an attacker to bypass security rules. This bypass could lead to the execution of dangerous payloads that rely on line breaks, potentially resulting in a security compromise.
Отчет
This issue is classified as Moderate severity primarily because: Conditions for Exploitation: Successful exploitation requires a specific scenario where the backend application preserves line breaks and is inherently vulnerable to a payload that utilizes those line breaks. Additionally, the ModSecurity configuration must rely on rules inspecting the affected ARGS or ARGS_POST variables to allow the bypass to occur. Impact Limitations: The vulnerability functions solely as a security control bypass, allowing potentially malicious requests to evade the Web Application Firewall (WAF). It does not directly cause privilege escalation, data corruption, or arbitrary code execution on the host system. The actual impact depends entirely on whether the backend application being protected is vulnerable to the bypassed requests.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 7 | mod_security | Out of support scope | ||
| Red Hat Enterprise Linux 8 | mod_security | Fix deferred | ||
| Red Hat Enterprise Linux 9 | mod_security | Fix deferred |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
5.8 Medium
CVSS3
Связанные уязвимости
ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Prior to 3.0.16, the multipart/form-data request body parser in libmodsecurity silently removes embedded line breaks from non-file form-field values before exporting them to ARGS and ARGS_POST because src/request_body_processor/multipart.cc overwrites reserved bytes in m_reserve instead of appending the current buffer. This creates a parser differential between ModSecurity and backend applications that preserve line breaks in form fields, allowing rules that inspect ARGS or ARGS_POST to miss payloads whose dangerous syntax depends on a line break. This issue is fixed in version 3.0.16.
ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Prior to 3.0.16, the multipart/form-data request body parser in libmodsecurity silently removes embedded line breaks from non-file form-field values before exporting them to ARGS and ARGS_POST because src/request_body_processor/multipart.cc overwrites reserved bytes in m_reserve instead of appending the current buffer. This creates a parser differential between ModSecurity and backend applications that preserve line breaks in form fields, allowing rules that inspect ARGS or ARGS_POST to miss payloads whose dangerous syntax depends on a line break. This issue is fixed in version 3.0.16.
ModSecurity is an open source, cross platform web application firewall ...
5.8 Medium
CVSS3