Asymmetric denial of service In modsecurity-apache
Description
ModSecurity 3.x through 3.0.5 mishandles excessively nested JSON objects. Crafted JSON objects with nesting tens-of-thousands deep could result in the web server being unable to service legitimate requests. Even a moderately large (e.g., 300KB) HTTP request can occupy one of the limited NGINX worker processes for minutes and consume almost all of the available CPU on the machine. Modsecurity 2 is similarly vulnerable: the affected versions include 2.8.0 through 2.9.4.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 11 | 2.9.3-3+deb11u1 | ||
debian 12 | 3.0.6-1 | ||
debian 12 | 2.9.5-1 | ||
debian 13 | 3.0.6-1 | ||
debian 11 | - | ||
debian 14 | 2.9.5-1 | ||
debian 14 | 3.0.6-1 | ||
debian 13 | 2.9.5-1 |
Aliases
1. 2. 3. 4. 5.
References
1.