Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 923858 (CVE-2024-1019) - dev-libs/modsecurity: WAF bypass
Summary: dev-libs/modsecurity: WAF bypass
Status: IN_PROGRESS
Alias: CVE-2024-1019
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL: B4 [glsa? cleanup]
Whiteboard:
Keywords:
Depends on: 923857
Blocks:
  Show dependency tree
 
Reported: 2024-02-06 04:55 UTC by Tomáš Mózes
Modified: 2024-02-06 07:35 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Tomáš Mózes 2024-02-06 04:55:31 UTC
https://nvd.nist.gov/vuln/detail/CVE-2024-1019

https://github.com/owasp-modsecurity/ModSecurity/releases/tag/v3.0.12
Security impacting issue
  WAF bypass of the ModSecurity v3 release line for path-based payloads by submitting a specially crafted request URL. For details, see CVE 2024-1019.