PT-2024-31947 · Unknown · Modsecurity

Yoloflz101

·

Published

2024-10-09

·

Updated

2025-06-18

·

CVE-2024-46292

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions ModSecurity versions 3.0.12 and earlier
Description A buffer overflow in ModSecurity allows attackers to cause a Denial of Service (DoS) via a crafted input inserted into the name parameter. The issue is disputed by the supplier as it cannot be reproduced, and the product's documentation indicates that it is not guaranteed to be usable with very large values of SecRequestBodyNoFilesLimit, which are required by the claimed issue.
Recommendations For ModSecurity version 3.0.12, update to the latest release to mitigate risks. For all other affected versions, update to the latest version as detailed in the official documentation. As a temporary workaround, consider restricting the use of the name parameter to minimize the risk of exploitation.

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-MODSECURITY-2024-46292
BIT-MODSECURITY2-2024-46292
CVE-2024-46292

Affected Products

Modsecurity