ModSecurity 3.x through 3.0.5 mishandles excessively nested JSON objects. Crafted JSON objects with nesting tens-of-thousands deep could result in the web server being unable to service legitimate requests. Even a moderately large (e.g., 300KB) HTTP request can occupy one of the limited NGINX worker processes for minutes and consume almost all of the available CPU on the machine. Modsecurity 2 is similarly vulnerable: the affected versions include 2.8.0 through 2.9.4.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade modsecurityUpgrade modsecurity-apache | Dec 20, 2021 | Dec 7, 2021 |
| Huawei Euleros 2_0_sp5 | — | Upgrade mod_security | Mar 22, 2022 | Dec 7, 2021 |
| Huawei Euleros 2_0_sp8 | — | Upgrade mod_security | Mar 29, 2022 | Dec 7, 2021 |
| Oracle Solaris | — | Upgrade web/server/apache-24/module/apache-security to version 2.9.5-11.4.42.0.1.113.0 on Solaris 11.4 | Feb 17, 2022 | Dec 7, 2021 |
| Suse | — | Upgrade libmodsecurity3-64bitUpgrade libmodsecurity3Upgrade libmodsecurity3-32bitUpgrade modsecurityUpgrade modsecurity-devel | Aug 9, 2024 | Dec 7, 2021 |
| Ubuntu | — | Upgrade libapache2-modsecurity (Ubuntu Pro)Upgrade libapache2-mod-security2 (Ubuntu Pro)Upgrade libapache2-mod-security2 | Sep 18, 2023 | Dec 7, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub