HIGH · 7.5

CVE-2021-42717

ModSecurity 3.x through 3.0.5 mishandles excessively nested JSON objects. Crafted JSON objects with nesting tens-of-thousands deep could result in the web server being unable to service legitimate req...

Vulnerability Description

ModSecurity 3.x through 3.0.5 mishandles excessively nested JSON objects. Crafted JSON objects with nesting tens-of-thousands deep could result in the web server being unable to service legitimate requests. Even a moderately large (e.g., 300KB) HTTP request can occupy one of the limited NGINX worker processes for minutes and consume almost all of the available CPU on the machine. Modsecurity 2 is similarly vulnerable: the affected versions include 2.8.0 through 2.9.4.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
OwaspModsecurity>= 3.0.0, < 3.0.6
TrustwaveModsecurity>= 2.0.0, < 2.9.5
F5Nginx Modsecurity Wafr24
DebianDebian Linux9.0
OracleHttp Server12.2.1.3.0
OracleZfs Storage Appliance Kit8.8

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-42717?

CVE-2021-42717 is a vulnerability with a CVSS score of 7.5 (HIGH). ModSecurity 3.x through 3.0.5 mishandles excessively nested JSON objects. Crafted JSON objects with nesting tens-of-thousands deep could result in the web server being unable to service legitimate req...

How severe is CVE-2021-42717?

CVE-2021-42717 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-42717?

Check the references section above for vendor advisories and patch information. Affected products include: Owasp Modsecurity, Trustwave Modsecurity, F5 Nginx Modsecurity Waf, Debian Debian Linux, Oracle Http Server.