发布时间: 2025年6月27日
修改时间: 2025年7月11日
ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Versions prior to 2.9.10 contain a denial of service vulnerability similar to GHSA-859r-vvv8-rm8r/CVE-2025-47947. The `sanitiseArg` (and `sanitizeArg` - this is the same action but an alias) is vulnerable to adding an excessive number of arguments, thereby leading to denial of service. Version 2.9.10 fixes the issue. As a workaround, avoid using rules that contain the `sanitiseArg` (or `sanitizeArg`) action.
NVD | openEuler | |
---|---|---|
Confidentiality | None | |
Attack Vector | Network | |
CVSS评分 | N/A | 7.5 |
Attack Complexity | Low | |
Privileges Required | None | |
Scope | Unchanged | |
Integrity | None | |
User Interaction | None | |
Availability | High |
公告名 | 概要 | 发布时间 |
---|---|---|
KylinSec-SA-2025-2663 | mod_security security update | 2025年7月4日 |
产品 | 包 | 状态 |
---|---|---|
KY3.4-5A | mod_security | Fixed |
V6 | mod_security | Fixed |
KY3.5.3 | mod_security | Fixed |
KY3.5.2 | mod_security | Fixed |