PT-2020-6759 · Trustwave · Modsecurity

Ervin Hegedues

·

Published

2020-09-14

·

Updated

2025-07-03

·

CVE-2020-15598

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Trustwave ModSecurity versions 3.x through 3.0.4
Description The issue is related to the handling of regular expressions in Trustwave ModSecurity, which can result in a Denial of Service condition. An attacker would need to know that a rule using a potentially problematic regular expression was in place and the basic nature of the regular expression itself to exploit any resource issues. It is well known that regular expression usage can be taxing on system resources regardless of the use case. The vendor does not consider this as a security issue, as there is no default configuration issue and it is up to the administrator to decide on when it is appropriate to trade resources for potential security benefit.
Recommendations For Trustwave ModSecurity versions 3.x through 3.0.4, consider restricting the use of regular expressions in rules to minimize the risk of exploitation. As a temporary workaround, consider disabling rules that use potentially problematic regular expressions until a patch is available. Administrators should review their configuration and decide on the appropriate trade-off between resources and potential security benefits. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Infinite Loop

Resource Exhaustion

Weakness Enumeration

Related Identifiers

BDU:2022-06098
BIT-MODSECURITY-2020-15598
BIT-MODSECURITY2-2020-15598
CVE-2020-15598
DSA-4765-1
OPENSUSE-SU-2023:0257-1
OPENSUSE-SU-2023:0269-1
OPENSUSE-SU-2024:12118-1

Affected Products

Modsecurity