PT-2021-4072 · Unknown · Modsecurity
Published
2021-05-06
·
Updated
2025-07-03
·
CVE-2019-25043
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
ModSecurity versions 3.x before 3.0.4
ModSecurity version 3.0.4 is not affected, so the range can be simplified to versions prior to 3.0.4.
Description
The issue is related to incorrect parsing of key-value pairs, which can lead to a "string index out of range" error and cause a worker-process crash. This can be triggered by a "Cookie: =abc" header. The vulnerability can be exploited by a remote attacker to cause a denial of service.
Recommendations
For versions prior to 3.0.4, update to version 3.0.4 or later to resolve the issue.
As a temporary workaround, consider restricting access to the Cookie header to minimize the risk of exploitation.
Exploit
Fix
Improper Handling of Exceptional Conditions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Modsecurity