PT-2021-4072 · Unknown · Modsecurity

Published

2021-05-06

·

Updated

2025-07-03

·

CVE-2019-25043

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions ModSecurity versions 3.x before 3.0.4 ModSecurity version 3.0.4 is not affected, so the range can be simplified to versions prior to 3.0.4.
Description The issue is related to incorrect parsing of key-value pairs, which can lead to a "string index out of range" error and cause a worker-process crash. This can be triggered by a "Cookie: =abc" header. The vulnerability can be exploited by a remote attacker to cause a denial of service.
Recommendations For versions prior to 3.0.4, update to version 3.0.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the Cookie header to minimize the risk of exploitation.

Exploit

Fix

Improper Handling of Exceptional Conditions

Weakness Enumeration

Related Identifiers

BDU:2021-04618
CVE-2019-25043

Affected Products

Modsecurity