RSS   Vulnerabilities for 'Nginx modsecurity waf'   RSS

2021-12-07
 
CVE-2021-42717

CWE-674
 

 
ModSecurity 3.x through 3.0.5 mishandles excessively nested JSON objects. Crafted JSON objects with nesting tens-of-thousands deep could result in the web server being unable to service legitimate requests. Even a moderately large (e.g., 300KB) HTTP request can occupy one of the limited NGINX worker processes for minutes and consume almost all of the available CPU on the machine. Modsecurity 2 is similarly vulnerable: the affected versions include 2.8.0 through 2.9.4.

 

 >>> Vendor: F5 76 Products
Big-ip
Icontrol service manager
Enterprise manager
Firepass 4100
Firepass 1000
Firepass
Firepass ssl vpn
Firepass 1200
Nginx
Big-ip application security manager
Big-ip protocol security manager
Mobilesafe
Big-ip local traffic manager
Big-ip global traffic manager
Application security manager appliance
Big-ip access policy manager
Big-ip edge gateway
Big-ip link controller
Big-ip protocol security module
Big-ip wan optimization manager
Big-ip webaccelerator
Big-ip configuration utility
Big-ip analytics
Big-iq
Big-ip advanced firewall manager
Big-ip application acceleration manager
Big-ip policy enforcement manager
Arx data manager
ARX
Big-iq cloud
Big-iq device
Big-iq security
Linerate
Big-ip policy enforcement manager11.5.1
Big-iq adc
Big-ip enterprise manager
Big-ip domain name system
Big-ip global traffic manager11.2.0
Big-iq application delivery controller
Big-iq centralized management
Big-iq cloud and orchestration
Big-ip websafe
F5 iworkflow
Ssl intercept iapp
Ssl orchestrator
Big-ip aam
Big-ip afm
Big-ip apm
Big-ip asm
Big-ip ltm
Big-ip pem
Websafe
Big-ip dns
Big-ip fraud protection service
Traffix systems signaling delivery controller
Big-ip access policy manager client
TMOS
Traffix signaling delivery controller
Big-ip webaccelerator12.1.1
Traffix sdc
NJS
Websafe alert server
Iworkflow
Container ingress service
Big-ip controller
Nginx controller
Big-ip advanced web application firewall
Big-ip ddos hybrid defender
Big-ip ssl orchestrator
Big-ip carrier-grade nat
Access policy manager clients
Nginx modsecurity waf
Nginx controller api management
Access for android
Nginx service mesh
Big-ip guided configuration


Copyright 2024, cxsecurity.com

 

Back to Top