CVE-2020-15598
modsecurity - security update
描述
Trustwave ModSecurity 3.x through 3.0.4 allows denial of service via a special request. NOTE: The discoverer reports "Trustwave has signaled they are disputing our claims." The CVE suggests that there is a security issue with how ModSecurity handles regular expressions that can result in a Denial of Service condition. The vendor does not consider this as a security issue because1) there is no default configuration issue here. An attacker would need to know that a rule using a potentially problematic regular expression was in place, 2) the attacker would need to know the basic nature of the regular expression itself to exploit any resource issues. It's well known that regular expression usage can be taxing on system resources regardless of the use case. It is up to the administrator to decide on when it is appropriate to trade resources for potential security benefit
如何修補 CVE-2020-15598
要修補 CVE-2020-15598,請將受影響套件升級到下列已修補版本。
- —升級至 3.0.5 或更新版本
- —升級至 3.0.5 或更新版本
- —升級至 3.0.4-2 或更新版本
- —升級至 3.0.3-1+deb10u2 或更新版本
CVE-2020-15598 正在被利用嗎?
低 — EPSS 為 3.2%,目前沒有觀察到大規模利用活動。
受影響套件(4)
- >= 3.0.0, < 3.0.5
- >= 3.0.0, < 3.0.5
- from 0, < 3.0.4-2
- from 0, < 3.0.3-1+deb10u2
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |