Show plain JSON{"bugzilla": {"description": "mod_security: DoS Vulnerability in Four Transformations", "id": "2226930", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2226930"}, "csaw": false, "cvss3": {"cvss3_base_score": "7.5", "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "status": "draft"}, "cwe": "CWE-400", "details": ["Trustwave ModSecurity 3.x before 3.0.10 has Inefficient Algorithmic Complexity.", "A vulnerability was found in Trustwave's ModSecurity project due to an inefficient algorithmic complexity flaw. This issue is present in four transformation actions: removeWhitespace, removeNull, replaceNull, and removeCommentsChar. By sending a maliciously crafted HTTP request, an attacker could trigger worst-case performance, causing a denial of service."], "name": "CVE-2023-38285", "package_state": [{"cpe": "cpe:/o:redhat:enterprise_linux:7", "fix_state": "Not affected", "package_name": "mod_security", "product_name": "Red Hat Enterprise Linux 7"}, {"cpe": "cpe:/o:redhat:enterprise_linux:8", "fix_state": "Not affected", "package_name": "mod_security", "product_name": "Red Hat Enterprise Linux 8"}, {"cpe": "cpe:/o:redhat:enterprise_linux:9", "fix_state": "Not affected", "package_name": "mod_security", "product_name": "Red Hat Enterprise Linux 9"}, {"cpe": "cpe:/a:redhat:jboss_core_services:1", "fix_state": "Not affected", "package_name": "jbcs-httpd24-mod_security", "product_name": "Red Hat JBoss Core Services"}, {"cpe": "cpe:/a:redhat:jboss_core_services:1", "fix_state": "Not affected", "package_name": "mod_security", "product_name": "Red Hat JBoss Core Services"}, {"cpe": "cpe:/a:redhat:rhel_software_collections:3", "fix_state": "Not affected", "package_name": "httpd24-mod_security", "product_name": "Red Hat Software Collections"}], "public_date": "2023-07-26T00:00:00Z", "references": ["https://www.cve.org/CVERecord?id=CVE-2023-38285\nhttps://nvd.nist.gov/vuln/detail/CVE-2023-38285\nhttps://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/modsecurity-v3-dos-vulnerability-in-four-transformations-cve-2023-38285/"], "statement": "ModSecurity v2.x is not affected. CVE-2023-38285 only affects ModSecurity v3.x releases. None of our products ship ModSecurity v3.x builds. Therefore, Red Hat Enterprise Linux, Red Hat Software Collections, and Red Hat JBoss Core Services are not affected by this CVE.", "threat_severity": "Moderate"}