CVE-2021-42717
Summary
| CVE | CVE-2021-42717 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-12-07 22:15:00 UTC |
| Updated | 2022-09-03 03:33:00 UTC |
| Description | ModSecurity 3.x through 3.0.5 mishandles excessively nested JSON objects. Crafted JSON objects with nesting tens-of-thousands deep could result in the web server being unable to service legitimate requests. Even a moderately large (e.g., 300KB) HTTP request can occupy one of the limited NGINX worker processes for minutes and consume almost all of the available CPU on the machine. Modsecurity 2 is similarly vulnerable: the affected versions include 2.8.0 through 2.9.4. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Oracle Critical Patch Update Advisory - April 2022 |
MISC |
www.oracle.com |
|
| [SECURITY] [DLA 3031-1] modsecurity-apache security update |
MLIST |
lists.debian.org |
|
| Debian -- Security Information -- DSA-5023-1 modsecurity-apache |
DEBIAN |
www.debian.org |
|
| ModSecurity DoS Vulnerability in JSON Parsing (CVE-2021-42717) | Trustwave |
MISC |
www.trustwave.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 178946 Debian Security Update for modsecurity-apache (DSA 5023-1)
- 179326 Debian Security Update for modsecurity-apache (DLA 3031-1)
- 184295 Debian Security Update for modsecurity-apachemodsecurity (CVE-2021-42717)
- 199752 Ubuntu Security Notification for ModSecurity Vulnerabilities (USN-6370-1)
- 296061 Oracle Solaris 11.4 Support Repository Update (SRU) 42.113.1 Missing (CPUJAN2022)
- 377911 Oracle Hypertext Transfer Protocol Server (HTTP Server) Multiple Vulnerabilities (CPUJAN2023)
- 671396 EulerOS Security Update for mod_security (EulerOS-SA-2022-1332)
- 671426 EulerOS Security Update for mod_security (EulerOS-SA-2022-1355)