Unrated severityNVD Advisory· Published Apr 28, 2023· Updated Jan 30, 2025
CVE-2023-28882
CVE-2023-28882
Description
Trustwave ModSecurity 3.0.5 through 3.0.8 before 3.0.9 allows a denial of service (worker crash and unresponsiveness) because some inputs cause a segfault in the Transaction class for some configurations.
Affected products
13- Trustwave/ModSecuritydescription
- osv-coords12 versionspkg:apk/chainguard/modsecuritypkg:apk/chainguard/modsecurity-configpkg:apk/chainguard/modsecurity-staticpkg:apk/wolfi/modsecuritypkg:apk/wolfi/modsecurity-configpkg:apk/wolfi/modsecurity-staticpkg:bitnami/modsecuritypkg:bitnami/modsecurity2pkg:rpm/opensuse/modsecurity&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/modsecurity&distro=openSUSE%20Leap%2015.5pkg:rpm/suse/modsecurity&distro=SUSE%20Package%20Hub%2015%20SP4pkg:rpm/suse/modsecurity&distro=SUSE%20Package%20Hub%2015%20SP5
< 3.0.9-r0+ 11 more
- (no CPE)range: < 3.0.9-r0
- (no CPE)range: < 3.0.9-r0
- (no CPE)range: < 3.0.9-r0
- (no CPE)range: < 3.0.9-r0
- (no CPE)range: < 3.0.9-r0
- (no CPE)range: < 3.0.9-r0
- (no CPE)range: >= 3.0.5, < 3.0.9
- (no CPE)range: >= 3.0.5, < 3.0.9
- (no CPE)range: < 3.0.10-bp154.2.3.1
- (no CPE)range: < 3.0.10-bp155.3.3.1
- (no CPE)range: < 3.0.10-bp154.2.3.1
- (no CPE)range: < 3.0.10-bp155.3.3.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.