Known Vulnerabilities for Modsecurity by Trustwave
Listed below are 10 of the newest known vulnerabilities associated with "Modsecurity" by "Trustwave".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2023-38285 json | Trustwave ModSecurity 3.x before 3.0.10 has Inefficient Algorithmic Complexity. | 7.5 - HIGH | 2023-07-26 | 2023-08-02 |
| CVE-2023-28882 json | Trustwave ModSecurity 3.0.5 through 3.0.8 before 3.0.9 allows a denial of service (worker crash and unresponsiveness) because... | 7.5 - HIGH | 2023-04-28 | 2023-05-04 |
| CVE-2023-24021 json | Incorrect handling of '\0' bytes in file uploads in ModSecurity before 2.9.7 may allow for Web Application Firewall bypasses ... | 7.5 - HIGH | 2023-01-20 | 2023-11-07 |
| CVE-2022-48279 json | In ModSecurity before 2.9.6 and 3.x before 3.0.8, HTTP multipart requests were incorrectly parsed and could bypass the Web Ap... | 7.5 - HIGH | 2023-01-20 | 2023-11-07 |
| CVE-2021-42717 json | ModSecurity 3.x through 3.0.5 mishandles excessively nested JSON objects. Crafted JSON objects with nesting tens-of-thousands... | 7.5 - HIGH | 2021-12-07 | 2022-09-03 |
| CVE-2020-15598 json | ** DISPUTED ** Trustwave ModSecurity 3.x through 3.0.4 allows denial of service via a special request. NOTE: The discoverer r... | 7.5 - HIGH | 2020-10-06 | 2023-11-07 |
| CVE-2019-25043 json | ModSecurity 3.x before 3.0.4 mishandles key-value pair parsing, as demonstrated by a "string index out of range" error and wo... | 5.3 - MEDIUM | 2021-05-06 | 2021-05-14 |
| CVE-2019-19886 json | Trustwave ModSecurity 3.0.0 through 3.0.3 allows an attacker to send crafted requests that may, when sent quickly in large vo... | 7.5 - HIGH | 2020-01-21 | 2023-11-07 |
| CVE-2018-13065 json | ** DISPUTED ** ModSecurity 3.0.0 has XSS via an onerror attribute of an IMG element. NOTE: a third party has disputed this is... | 6.1 - MEDIUM | 2018-07-03 | 2023-11-07 |
| CVE-2013-5705 json | apache2/modsecurity.c in ModSecurity before 2.7.6 allows remote attackers to bypass rules by using chunked transfer coding wi... | 5 - MEDIUM | 2014-04-15 | 2021-02-12 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Trustwave | Modsecurity | 3.0.4 | |||
| Application | Trustwave | Modsecurity | 3.0.3 | |||
| Application | Trustwave | Modsecurity | 3.0.2 | |||
| Application | Trustwave | Modsecurity | 3.0.1 | |||
| Application | Trustwave | Modsecurity | 3.0.0 | |||
| Application | Trustwave | Modsecurity | 2.9.3 | |||
| Application | Trustwave | Modsecurity | 2.9.2 | |||
| Application | Trustwave | Modsecurity | 2.9.1 | |||
| Application | Trustwave | Modsecurity | 2.9.1 | |||
| Application | Trustwave | Modsecurity | 2.9.0 | |||
| Application | Trustwave | Modsecurity | 2.9.0 | |||
| Application | Trustwave | Modsecurity | 2.9.0 | |||
| Application | Trustwave | Modsecurity | 2.8.0 | |||
| Application | Trustwave | Modsecurity | 2.8.0 | |||
| Application | Trustwave | Modsecurity | 2.7.7 | |||
| Application | Trustwave | Modsecurity | 2.7.6 | |||
| Application | Trustwave | Modsecurity | 2.7.5 | |||
| Application | Trustwave | Modsecurity | 2.7.4 | |||
| Application | Trustwave | Modsecurity | 2.7.3 | |||
| Application | Trustwave | Modsecurity | 2.7.2 |