CVE-2019-25043: Medium severity trustwave modsecurity vulnerability
Published May 6, 2021
·Updated
ModSecurity 3.x before 3.0.4 mishandles key-value pair parsing, as demonstrated by a "string index out of range" error and worker-process crash for a "Cookie: =abc" header.
Affected Software
2 affected components
Trustwave ModSecurity>=3.0.0<3.0.4
OWASP Modsecurity>=3.0.0<3.0.4
Event History
May 6, 2021
CVE Published
via MITRE·04:32 PM
Data Sourced
via MITRE·04:32 PM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2019-25043?
CVE-2019-25043 is a vulnerability in ModSecurity 3.x before version 3.0.4 that mishandles key-value pair parsing, leading to a crash.
2
How does CVE-2019-25043 impact ModSecurity?
CVE-2019-25043 can cause a crash in ModSecurity worker processes when handling a specific "Cookie: =abc" header.
3
What is the severity of CVE-2019-25043?
CVE-2019-25043 has a severity rating of 5.3 (medium).
4
How can I fix CVE-2019-25043?
To fix CVE-2019-25043, upgrade ModSecurity to version 3.0.4 or later.
5
Where can I find more information about CVE-2019-25043?
More information about CVE-2019-25043 can be found at the following link: [CVE-2019-25043](https://github.com/SpiderLabs/ModSecurity/issues/2566).