Incorrect handling of '\0' bytes in file uploads in ModSecurity before 2.9.7 may allow for Web Application Firewall bypasses and buffer over-reads on the Web Application Firewall when executing rules that read the FILES_TMP_CONTENT collection.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | amazon-linux-ami-2-upgrade-mod_securityamazon-linux-ami-2-upgrade-mod_security-debuginfoamazon-linux-ami-2-upgrade-mod_security-mlogc | Jul 4, 2023 | Jan 20, 2023 | |
| Debian | debian-upgrade-modsecurity-apache | Jan 30, 2023 | Jan 20, 2023 | |
| Huawei Euleros 2_0_sp5 | huawei-euleros-2_0_sp5-upgrade-mod_security | Jun 9, 2023 | Jan 20, 2023 | |
| Huawei Euleros 2_0_sp8 | huawei-euleros-2_0_sp8-upgrade-mod_security | Apr 13, 2023 | Jan 20, 2023 | |
| Redhat_linux | — | no-fix-redhat-rpm-package | Jul 9, 2025 | Jan 20, 2023 |
| Suse | — | suse-upgrade-apache2-mod_security2 | Feb 16, 2023 | Jan 20, 2023 |
| Ubuntu | ubuntu-pro-upgrade-libapache2-mod-security2ubuntu-pro-upgrade-libapache2-modsecurityubuntu-upgrade-libapache2-mod-security2 | Sep 18, 2023 | Jan 20, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub