CVE-2019-19886: High severity modsecurity vulnerability
Trustwave ModSecurity 3.0.0 through 3.0.3 allows an attacker to send crafted requests that may, when sent quickly in large volumes, lead to the server becoming slow or unresponsive (Denial of Service) because of a flaw in Transaction::addRequestHeader in transaction.cc.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-19886?
CVE-2019-19886 is a vulnerability in Trustwave ModSecurity 3.0.0 through 3.0.3 that allows an attacker to send crafted requests that may lead to a Denial of Service.
What is the severity of CVE-2019-19886?
CVE-2019-19886 has a severity value of 7.5 (high).
Which software versions are affected by CVE-2019-19886?
Trustwave ModSecurity versions 3.0.0 through 3.0.3 and Fedora versions 30, 31, and 32 are affected by CVE-2019-19886.
How can an attacker exploit CVE-2019-19886?
An attacker can exploit CVE-2019-19886 by sending crafted requests quickly and in large volumes, causing the server to become slow or unresponsive.
Are there any fixes or patches available for CVE-2019-19886?
Yes, patches are available for Trustwave ModSecurity and Fedora to address the vulnerability. Please refer to the provided references for more information.