Vulnerability Description
A buffer overflow in modsecurity v3.0.12 allows attackers to cause a Denial of Service (DoS) via a crafted input inserted into the name parameter. NOTE: this is disputed by the Supplier because it cannot be reproduced. Also, the product's documentation indicates that it is not guaranteed to be usable with very large values of SecRequestBodyNoFilesLimit (which are required by the claimed issue).
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Trustwave | Modsecurity | 3.0.12 |
Related Weaknesses (CWE)
References
- https://github.com/owasp-modsecurity/ModSecurity/blob/v3/master/README.mdVendor Advisory
- https://github.com/yoloflz101/yoloflz/blob/main/README.mdBroken Link
- https://modsecurity.org/20241011/about-cve-2024-46292-2024-october/Vendor Advisory
FAQ
What is CVE-2024-46292?
CVE-2024-46292 is a vulnerability with a CVSS score of 7.5 (HIGH). A buffer overflow in modsecurity v3.0.12 allows attackers to cause a Denial of Service (DoS) via a crafted input inserted into the name parameter. NOTE: this is disputed by the Supplier because it can...
How severe is CVE-2024-46292?
CVE-2024-46292 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-46292?
Check the references section above for vendor advisories and patch information. Affected products include: Trustwave Modsecurity.