PT-2024-1513 · Unknown+3 · Modsecurity+4

Airween

+6

·

Published

2024-01-30

·

Updated

2026-03-18

·

CVE-2024-1019

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions ModSecurity / libModSecurity versions 3.0.0 through 3.0.11
Description The issue is related to a WAF bypass for path-based payloads submitted via specially crafted request URLs. ModSecurity v3 decodes percent-encoded characters present in request URLs before it separates the URL path component from the optional query string component, resulting in an impedance mismatch versus RFC compliant back-end applications. This hides an attack payload in the path component of the URL from WAF rules inspecting it. A back-end may be vulnerable if it uses the path component of request URLs to construct queries.
Recommendations For ModSecurity / libModSecurity versions 3.0.0 through 3.0.11, upgrade to version 3.0.12 to resolve the issue. As a temporary workaround, consider restricting the use of percent-encoded characters in request URLs to minimize the risk of exploitation. Additionally, review and adjust WAF rules to ensure they properly inspect the URL path component.

Fix

RCE

Weakness Enumeration

Related Identifiers

ALT-PU-2024-4741
ALT-PU-2025-3441
BDU:2024-01024
BIT-MODSECURITY-2024-1019
BIT-MODSECURITY2-2024-1019
CVE-2024-1019
OPENSUSE-SU-2024:13732-1

Affected Products

Alt Linux
Debian
Modsecurity
Red Os
Libmodsecurity