Vulnerability Description
Trustwave ModSecurity 3.0.5 through 3.0.8 before 3.0.9 allows a denial of service (worker crash and unresponsiveness) because some inputs cause a segfault in the Transaction class for some configurations.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Owasp | Modsecurity | >= 3.0.5, < 3.0.9 |
Related Weaknesses (CWE)
References
- https://www.trustwave.com/en-us/resources/security-resources/software-updates/anRelease Notes
- https://www.trustwave.com/en-us/resources/security-resources/software-updates/anRelease Notes
FAQ
What is CVE-2023-28882?
CVE-2023-28882 is a vulnerability with a CVSS score of 7.5 (HIGH). Trustwave ModSecurity 3.0.5 through 3.0.8 before 3.0.9 allows a denial of service (worker crash and unresponsiveness) because some inputs cause a segfault in the Transaction class for some configurati...
How severe is CVE-2023-28882?
CVE-2023-28882 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-28882?
Check the references section above for vendor advisories and patch information. Affected products include: Owasp Modsecurity.