5
CVSSv2

CVE-2019-11389

Published: 21/04/2019 Updated: 11/04/2024
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

An issue exists in OWASP ModSecurity Core Rule Set (CRS) up to and including 3.1.0. /rules/REQUEST-933-APPLICATION-ATTACK-PHP.conf allows remote malicious users to cause a denial of service (ReDOS) by entering a specially crafted string with next# at the beginning and nested repetition operators. NOTE: the software maintainer disputes that this is a vulnerability because the issue cannot be exploited via ModSecurity

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

modsecurity owasp modsecurity core rule set

Vendor Advisories

Debian Bug report logs - #928053 CVE-2019-11387 CVE-2019-11388 CVE-2019-11389 CVE-2019-11390 CVE-2019-11391 Package: modsecurity-crs; Maintainer for modsecurity-crs is Alberto Gonzalez Iniesta <agi@inittaborg>; Source for modsecurity-crs is src:modsecurity-crs (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@de ...