CVE-2023-24021: High severity Trustwave ModSecurity vulnerability
In ModSecurity before 2.9.7, FILESTMPCONTENT sometimes lacked the complete content. This can lead to a Web Application Firewall bypass.
https://github.com/SpiderLabs/ModSecurity/pull/2857/commits/4324f0ac59f8225aa44bc5034df60dbeccd1d334 https://github.com/SpiderLabs/ModSecurity/releases/tag/v2.9.7 https://github.com/SpiderLabs/ModSecurity/pull/2857
Other sources
Incorrect handling of '\0' bytes in file uploads in ModSecurity before 2.9.7 may allow for Web Application Firewall bypasses and buffer over-reads on the Web Application Firewall when executing rules that read the FILESTMPCONTENT collection.
— Ubuntu
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ubuntu/modsecurity-apacheto a version that resolves this vulnerability.Fixed in 2.9.2-1ubuntu0.1~ - Upgrade
Upgrade
ubuntu/modsecurity-apacheto a version that resolves this vulnerability.Fixed in 2.9.3-1ubuntu0.1 - Upgrade
Upgrade
ubuntu/modsecurity-apacheto a version that resolves this vulnerability.Fixed in 2.9.5-1ubuntu0.1~ - Upgrade
Upgrade
ubuntu/modsecurity-apacheto a version that resolves this vulnerability.Fixed in 2.9.0-1ubuntu0.1~ - Upgrade
Upgrade
ubuntu/modsecurity-apacheto a version that resolves this vulnerability.Fixed in 2.9.7-1 - Upgrade
Upgrade
debian/modsecurity-apacheto a version that resolves this vulnerability.Fixed in 2.9.3-1+deb10u2Fixed in 2.9.3-3+deb11u2Fixed in 2.9.7-1 - Upgrade
Upgrade
redhat/ModSecurityto a version that resolves this vulnerability.Fixed in 2.9.7 - Upgrade
Upgrade
SpiderLabs/ModSecurityto a version that resolves this vulnerability.Fixed in 2.9.7 - Compensating control
If you cannot upgrade immediately from ModSecurity before 2.9.7, mitigate potential Web Application Firewall bypasses and buffer over-reads by adding/adjusting compensating WAF controls (e.g., rules/filters) to prevent exploitation of file-upload handling that affects the FILES_TMP_CONTENT collection.
Event History
Frequently Asked Questions
What is CVE-2023-24021?
CVE-2023-24021 is a vulnerability in ModSecurity before 2.9.7 that allows for Web Application Firewall bypasses and buffer over-reads when handling '\0' bytes in file uploads.
How does CVE-2023-24021 affect ModSecurity?
CVE-2023-24021 affects ModSecurity versions before 2.9.7, allowing for Web Application Firewall bypasses and buffer over-reads.
What is the severity of CVE-2023-24021?
The severity of CVE-2023-24021 is medium (CVSS score of 4).
How do I fix CVE-2023-24021?
To fix CVE-2023-24021, update ModSecurity to version 2.9.7 or later.
Where can I find more information about CVE-2023-24021?
You can find more information about CVE-2023-24021 on the official ModSecurity GitHub page and the provided references.