AZL-44934
Dashboard / Vulnerabilities / AZL-44934
Summary: CVE-2021-42717 affecting package mod_security for versions less than 2.9.7-8
Details: ModSecurity 3.x through 3.0.5 mishandles excessively nested JSON objects. Crafted JSON objects with nesting tens-of-thousands deep could result in the web server being unable to service legitimate requests. Even a moderately large (e.g., 300KB) HTTP request can occupy one of the limited NGINX worker processes for minutes and consume almost all of the available CPU on the machine. Modsecurity 2 is similarly vulnerable: the affected versions include 2.8.0 through 2.9.4.
References: https://nvd.nist.gov/vuln/detail/CVE-2021-42717
Affected packages
Package
Name: mod_security
Purl: pkg:rpm/azure-linux/mod_security
Affected ranges
Type: ECOSYSTEM
Events:
Introduced- 0
Fixed -2.9.7-8
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
