VDB
BDU%3A2023-07547
BDU%3A2023-07547
PUBLISHED
CVSS 9.399999618530273 CRITICAL
Уязвимость WAF движка для Apache ModSecurity, связанная с ошибками в настройках безопасности, позволяющая нарушителю обойти существующие правила межсетевого экрана
Risk Scores
CVSS 2.0
9.399999618530273
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat Inc., Novell Inc., Сообщество свободного программного обеспечения, Fedora Project, SpiderLabs | Red Hat Enterprise Linux, SUSE Linux Enterprise Server for SAP Applications, Debian GNU/Linux, Red Hat Software Collections, Suse Linux Enterprise Server, Fedora, ModSecurity, Red Hat JBoss Core Services | |
| n/a | n/a | n/a |
Timeline
- Nov 9, 2023 CVE Published
- Apr 12, 2024 CVE Updated
References
- https://github.com/SpiderLabs/ModSecurity/releases/tag/v2.9.7 url
- https://access.redhat.com/security/cve/cve-2023-24021 url
- https://security-tracker.debian.org/tracker/CVE-2023-24021 url
- https://www.suse.com/security/cve/CVE-2023-24021.html url
- https://github.com/SpiderLabs/ModSecurity/pull/2857 url
- https://github.com/SpiderLabs/ModSecurity/pull/2857/commits/4324f0ac59f8225aa44bc5034df60dbeccd1d334 url
- https://access.redhat.com/products/red-hat-jboss-core-services-collection/ advisory
- [debian-lts-announce] 20230126 [SECURITY] [DLA 3283-1] modsecurity-apache security update mailing-list
- FEDORA-2023-8aa264d5c5 vendor-advisory
- FEDORA-2023-09f0496e60 vendor-advisory
- FEDORA-2023-bc61f7a145 vendor-advisory