Vulnerabilities > Trustwave > Modsecurity > 3.0.4

DATE CVE VULNERABILITY TITLE RISK
2024-01-30 CVE-2024-1019 Unspecified vulnerability in Trustwave Modsecurity
ModSecurity / libModSecurity 3.0.0 to 3.0.11 is affected by a WAF bypass for path-based payloads submitted via specially crafted request URLs.
network
low complexity
trustwave
8.6
2023-07-26 CVE-2023-38285 Algorithmic Complexity vulnerability in Trustwave Modsecurity
Trustwave ModSecurity 3.x before 3.0.10 has Inefficient Algorithmic Complexity.
network
low complexity
trustwave CWE-407
7.5
2023-01-20 CVE-2022-48279 Interpretation Conflict vulnerability in multiple products
In ModSecurity before 2.9.6 and 3.x before 3.0.8, HTTP multipart requests were incorrectly parsed and could bypass the Web Application Firewall.
network
low complexity
trustwave debian CWE-436
7.5
2021-12-07 CVE-2021-42717 Uncontrolled Recursion vulnerability in multiple products
ModSecurity 3.x through 3.0.5 mishandles excessively nested JSON objects.
network
low complexity
trustwave f5 debian oracle CWE-674
5.0
2020-10-06 CVE-2020-15598 Infinite Loop vulnerability in multiple products
Trustwave ModSecurity 3.x through 3.0.4 allows denial of service via a special request.
network
low complexity
trustwave debian CWE-835
7.5