PT-2024-31947 · Unknown · Modsecurity
Yoloflz101
·
Published
2024-10-09
·
Updated
2025-06-18
·
CVE-2024-46292
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
ModSecurity versions 3.0.12 and earlier
Description
A buffer overflow in ModSecurity allows attackers to cause a Denial of Service (DoS) via a crafted input inserted into the
name parameter. The issue is disputed by the supplier as it cannot be reproduced, and the product's documentation indicates that it is not guaranteed to be usable with very large values of SecRequestBodyNoFilesLimit, which are required by the claimed issue.Recommendations
For ModSecurity version 3.0.12, update to the latest release to mitigate risks.
For all other affected versions, update to the latest version as detailed in the official documentation.
As a temporary workaround, consider restricting the use of the
name parameter to minimize the risk of exploitation.Fix
DoS
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Modsecurity