VDB
CVE-2019-19886
CVE-2019-19886
REJECTED
CVSS 7.5 HIGH
Trustwave ModSecurity 3.0.0 through 3.0.3 allows an attacker to send crafted requests that may, when sent quickly in large volumes, lead to the server becoming slow or unresponsive (Denial of Service) because of a flaw in Transaction::addRequestHeader in transaction.cc.
EPSS 2.50% · 83.6th percentile
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
2.50%
83.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:20.04:LTS | modsecurity | 0, 3.0.3-1 |
Timeline
- Jan 21, 2020 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Sep 17, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Feb 28, 2022 EPSS Score
- May 2, 2022 EPSS Score
- Jul 4, 2022 EPSS Score
- Nov 7, 2022 EPSS Score
- Jan 9, 2023 EPSS Score
References
- https://ubuntu.com/security/CVE-2019-19886 third-party-advisory
- https://github.com/SpiderLabs/ModSecurity/pull/2202 third-party-advisory
- https://github.com/SpiderLabs/ModSecurity/commit/7ba77631f9a37e0680d23ee57c455c6a35c65cb9 third-party-advisory
- https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/modsecurity-denial-of-service-details-cve-2019-19886/ third-party-advisory
- https://www.cve.org/CVERecord?id=CVE-2019-19886 third-party-advisory