CVE-2021-42717
published 2021-12-07CVE-2021-42717: ModSecurity 3.x through 3.0.5 mishandles excessively nested JSON objects. Crafted JSON objects with nesting tens-of-thousands deep could result in the web…
PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
3.21%
86.8th percentile
ModSecurity 3.x through 3.0.5 mishandles excessively nested JSON objects. Crafted JSON objects with nesting tens-of-thousands deep could result in the web server being unable to service legitimate requests. Even a moderately large (e.g., 300KB) HTTP request can occupy one of the limited NGINX worker processes for minutes and consume almost all of the available CPU on the machine. Modsecurity 2 is similarly vulnerable: the affected versions include 2.8.0 through 2.9.4.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | modsecurity | < modsecurity 3.0.6-1 (bookworm) | modsecurity 3.0.6-1 (bookworm) |
| debian | modsecurity-apache | < modsecurity 3.0.6-1 (bookworm) | modsecurity 3.0.6-1 (bookworm) |
| f5 | nginx_modsecurity_waf | — | — |
| f5 | nginx_modsecurity_waf | — | — |
| oracle | http_server | — | — |
| oracle | http_server | — | — |
| oracle | zfs_storage_appliance_kit | — | — |
| owasp | modsecurity | >= 3.0.0 < 3.0.6 | 3.0.6 |
| trustwave | modsecurity | >= 0 < 3.0.6-1 | 3.0.6-1 |
| trustwave | modsecurity | >= 0 < 3.0.6-1 | 3.0.6-1 |
| trustwave | modsecurity | >= 0 < 3.0.6-1 | 3.0.6-1 |
| trustwave | modsecurity | >= 2.0.0 < 2.9.5 | 2.9.5 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_oracle7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
modsecurity-apache vulnerabilities
osv·2023-09-14·CVSS 7.5
CVE-2021-42717 [HIGH] modsecurity-apache vulnerabilities
modsecurity-apache vulnerabilities
It was discovered that ModSecurity incorrectly handled certain nested JSON
objects. An attacker could possibly use this issue to cause a denial
of service. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS
and Ubuntu 20.04 LTS. (CVE-2021-42717)
It was discovered that ModSecurity incorrectly handled certain HTTP
multipart requests. A remote attacker could possibly use this issue
to bypass ModSecurity restrictions. (CVE-2022-48279)
It was discovered that ModSecurity incorrectly handled certain file
uploads. A remote attacker could possibly use this issue to cause a
buffer overflow and a firewall failure. This issue only affected
Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and Ubuntu 22.04 LTS.
(CVE-2023-24021)
GHSA
GHSA-w3vf-7fpc-9fww: ModSecurity 3
ghsa_unreviewed·2021-12-08
CVE-2021-42717 [HIGH] CWE-674 GHSA-w3vf-7fpc-9fww: ModSecurity 3
ModSecurity 3.x through 3.0.5 mishandles excessively nested JSON objects. Crafted JSON objects with nesting tens-of-thousands deep could result in the web server being unable to service legitimate requests. Even a moderately large (e.g., 300KB) HTTP request can occupy one of the limited NGINX worker processes for minutes and consume almost all of the available CPU on the machine. Modsecurity 2 is similarly vulnerable: the affected versions include 2.8.0 through 2.9.4.
OSV
CVE-2021-42717: ModSecurity 3
osv·2021-12-07·CVSS 7.5
CVE-2021-42717 [HIGH] CVE-2021-42717: ModSecurity 3
ModSecurity 3.x through 3.0.5 mishandles excessively nested JSON objects. Crafted JSON objects with nesting tens-of-thousands deep could result in the web server being unable to service legitimate requests. Even a moderately large (e.g., 300KB) HTTP request can occupy one of the limited NGINX worker processes for minutes and consume almost all of the available CPU on the machine. Modsecurity 2 is similarly vulnerable: the affected versions include 2.8.0 through 2.9.4.
Ubuntu
ModSecurity vulnerabilities
vendor_ubuntu·2023-09-14·CVSS 7.5
CVE-2021-42717 [HIGH] ModSecurity vulnerabilities
Title: ModSecurity vulnerabilities
Summary: Several security issues were fixed in ModSecurity.
It was discovered that ModSecurity incorrectly handled certain nested JSON
objects. An attacker could possibly use this issue to cause a denial
of service. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS
and Ubuntu 20.04 LTS. (CVE-2021-42717)
It was discovered that ModSecurity incorrectly handled certain HTTP
multipart requests. A remote attacker could possibly use this issue
to bypass ModSecurity restrictions. (CVE-2022-48279)
It was discovered that ModSecurity incorrectly handled certain file
uploads. A remote attacker could possibly use this issue to cause a
buffer overflow and a firewall failure. This issue only affected
Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: SSL Module (ModSecurity) — CVE-2021-42717
vendor_oracle·2023-01-15·CVSS 7.5
CVE-2021-42717 [HIGH] Oracle Oracle Fusion Middleware Risk Matrix: SSL Module (ModSecurity) — CVE-2021-42717
Oracle Oracle Fusion Middleware Risk Matrix: SSL Module (ModSecurity) vulnerability
CVE: CVE-2021-42717
CVSS: 7.5
Protocol: HTTPS
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2023 (JAN 2023)
Debian
CVE-2021-42717: modsecurity - ModSecurity 3.x through 3.0.5 mishandles excessively nested JSON objects. Crafte...
vendor_debian·2021·CVSS 7.5
CVE-2021-42717 [HIGH] CVE-2021-42717: modsecurity - ModSecurity 3.x through 3.0.5 mishandles excessively nested JSON objects. Crafte...
ModSecurity 3.x through 3.0.5 mishandles excessively nested JSON objects. Crafted JSON objects with nesting tens-of-thousands deep could result in the web server being unable to service legitimate requests. Even a moderately large (e.g., 300KB) HTTP request can occupy one of the limited NGINX worker processes for minutes and consume almost all of the available CPU on the machine. Modsecurity 2 is similarly vulnerable: the affected versions include 2.8.0 through 2.9.4.
Scope: local
bookworm: resolved (fixed in 3.0.6-1)
bullseye: open
forky: resolved (fixed in 3.0.6-1)
sid: resolved (fixed in 3.0.6-1)
trixie: resolved (fixed in 3.0.6-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://lists.debian.org/debian-lts-announce/2022/05/msg00042.htmlhttps://www.debian.org/security/2021/dsa-5023https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/modsecurity-dos-vulnerability-in-json-parsing-cve-2021-42717/https://lists.debian.org/debian-lts-announce/2022/05/msg00042.htmlhttps://www.debian.org/security/2021/dsa-5023https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/modsecurity-dos-vulnerability-in-json-parsing-cve-2021-42717/
2021-12-07
Published