REDHAT-BUG-1879588: Medium severity modsecurity modsecurity vulnerability
ModSecurity v3.0.x is affected by a Denial of Service vulnerability due to the global matching of regular expressions. The combination of a non-anchored regular expression and the ModSecurity “capture” action can be exploited via a specially crafted payload.
Known Affected Software Configurations:
ModSecurity v3.0.0 ModSecurity v3.0.1 ModSecurity v3.0.2 ModSecurity v3.0.3 ModSecurity v3.0.4 (patch for this version available
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1879588?
The severity of REDHAT-BUG-1879588 is classified as Denial of Service.
What versions of ModSecurity are affected by REDHAT-BUG-1879588?
ModSecurity versions from 3.0.0 to 3.0.4 are affected by REDHAT-BUG-1879588.
How do I fix REDHAT-BUG-1879588?
To fix REDHAT-BUG-1879588, upgrade to a patched version of ModSecurity beyond 3.0.4.
What exploit is associated with REDHAT-BUG-1879588?
REDHAT-BUG-1879588 can be exploited using a specially crafted payload that targets non-anchored regular expressions.
Is it possible to mitigate REDHAT-BUG-1879588 without upgrading?
Mitigation of REDHAT-BUG-1879588 may be possible by disabling the capture action in ModSecurity configurations.